Microsoft IIS Request Header Buffer Overflow Vulnerability
BID:43138
Info
Microsoft IIS Request Header Buffer Overflow Vulnerability
| Bugtraq ID: | 43138 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-2730 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2010 12:00AM |
| Updated: | Oct 25 2010 03:38PM |
| Credit: | Travis Raybold of Rubicon West |
| Vulnerable: |
Microsoft IIS 7.5 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya CallPilot Unified Messaging 0 Avaya Aura Conferencing 6.0 Standard |
| Not Vulnerable: | |
Discussion
Microsoft IIS Request Header Buffer Overflow Vulnerability
Microsoft IIS is prone to a remote buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects IIS 7.5 on Windows 7 and Windows Server 2008 R2.
Microsoft IIS is prone to a remote buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects IIS 7.5 on Windows 7 and Windows Server 2008 R2.
Exploit / POC
Microsoft IIS Request Header Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft IIS Request Header Buffer Overflow Vulnerability
Solution:
The vendor released an advisory and updates. Please see the references for more information.
Microsoft IIS 7.5
Solution:
The vendor released an advisory and updates. Please see the references for more information.
Microsoft IIS 7.5
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB2271195)
http://www.microsoft.com/downloads/en/details.aspx?familyid=9578B1DE-F 2C1-4B37-9D82-69E929CAB6F3&displaylang=en -
Microsoft Security Update for Windows 7 for x64-based Systems (KB2271195)
http://www.microsoft.com/downloads/en/details.aspx?familyid=5F0C0454-C BB6-47ED-9227-98AA45B8CBDB&displaylang=en -
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB2271195)
http://www.microsoft.com/downloads/en/details.aspx?familyid=21ADF80D-2 67F-47CD-9C03-4B4854BA159F&displaylang=en -
Microsoft Security Update for Windows 7 (KB2271195)
http://www.microsoft.com/downloads/en/details.aspx?familyid=C843AFD9-B 6F2-48DE-91CC-1C0D481C2BE4&displaylang=en
References
Microsoft IIS Request Header Buffer Overflow Vulnerability
References:
References: