Microsoft IIS 4.0 URL Redirection DoS Vulnerability
BID:3191
Info
Microsoft IIS 4.0 URL Redirection DoS Vulnerability
| Bugtraq ID: | 3191 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2001 12:00AM |
| Updated: | Aug 16 2001 12:00AM |
| Credit: | Published in a Microsoft Security Bulletin MS01-044 on Aug 15, 2001. |
| Vulnerable: |
Microsoft IIS 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS 4.0 URL Redirection DoS Vulnerability
Due to the inproper handling of URL redirection in IIS 4.0, it is possible to cause a host to stop responding.
This vulnerability is currently being exploited by the 'Code Red' worm. Upon the worm sending a request attempting to infect the target host, IIS 4.0 will inproperly handle the unusal length of the request and fail.
A restart of the service is required in order to gain normal functionality.
It should be noted that the 'Code Red' worm attempts to exploit a previously discovered vulnerability BID 2880.
Due to the inproper handling of URL redirection in IIS 4.0, it is possible to cause a host to stop responding.
This vulnerability is currently being exploited by the 'Code Red' worm. Upon the worm sending a request attempting to infect the target host, IIS 4.0 will inproperly handle the unusal length of the request and fail.
A restart of the service is required in order to gain normal functionality.
It should be noted that the 'Code Red' worm attempts to exploit a previously discovered vulnerability BID 2880.
Exploit / POC
Microsoft IIS 4.0 URL Redirection DoS Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft IIS 4.0 URL Redirection DoS Vulnerability
Solution:
Microsoft has released the following patch which rectifies this issue:
Solution:
Microsoft has released the following patch which rectifies this issue:
References
Microsoft IIS 4.0 URL Redirection DoS Vulnerability
References:
References:
- A Very Real and Present Threat to the Internet (Microsoft)
- CERT Incident Note IN-2001-10: "Code Red" Worm Crashes IIS 4.0 Servers with URL (CERT)
- Microsoft Security Bulletin MS01-033 (Microsoft)
- Microsoft Security Bulletin MS01-044 (Microsoft)
- Microsoft Technet Security (Microsoft)
- MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerabili (SecurityFocus)