Microsoft IIS MIME Header Denial of Service Vulnerability
BID:3195
Info
Microsoft IIS MIME Header Denial of Service Vulnerability
| Bugtraq ID: | 3195 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2001 12:00AM |
| Updated: | Aug 15 2001 12:00AM |
| Credit: | Published in Microsoft Security Bulletin MS01-044 on Aug 15, 2001. |
| Vulnerable: |
Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: |
Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Advanced Server SP3 |
Discussion
Microsoft IIS MIME Header Denial of Service Vulnerability
A flaw exists in version 5.0 of Microsoft IIS that makes it subject to a potential denial of service attack.
The problem occurs when the server is preparing the MIME headers for the response to a HTTP request for a certain type of file. Under certain circumstances, a failure causing the server to stop responding may occur.
In order for this vulnerability to be successfully exploited, a user would need appropriate permissions to add content to the web server.
No further technical details are available at this time.
A flaw exists in version 5.0 of Microsoft IIS that makes it subject to a potential denial of service attack.
The problem occurs when the server is preparing the MIME headers for the response to a HTTP request for a certain type of file. Under certain circumstances, a failure causing the server to stop responding may occur.
In order for this vulnerability to be successfully exploited, a user would need appropriate permissions to add content to the web server.
No further technical details are available at this time.
Exploit / POC
Microsoft IIS MIME Header Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft IIS MIME Header Denial of Service Vulnerability
References:
References:
- Microsoft Security Bulletin MS01-044 (Microsoft)
- Microsoft Technet Security (Microsoft)
- Secure Internet Information Services 5 Checklist (Microsoft)