Microsoft IIS Repeated Parameter Request Denial of Service Vulnerability
BID:43140
Info
Microsoft IIS Repeated Parameter Request Denial of Service Vulnerability
| Bugtraq ID: | 43140 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2010-1899 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2010 12:00AM |
| Updated: | Oct 01 2010 07:30PM |
| Credit: | Jinsik Shim |
| Vulnerable: |
Microsoft IIS 7.5 Microsoft IIS 7.0 Microsoft IIS 5.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya CallPilot Unified Messaging 0 Avaya Aura Conferencing 6.0 Standard |
| Not Vulnerable: | |
Discussion
Microsoft IIS Repeated Parameter Request Denial of Service Vulnerability
Microsoft IIS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to force the affected application to become unresponsive, denying service to legitimate users.
This issue affects IIS 5.1, 6.0, 7.0, and 7.5.
Microsoft IIS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to force the affected application to become unresponsive, denying service to legitimate users.
This issue affects IIS 5.1, 6.0, 7.0, and 7.5.
Exploit / POC
Microsoft IIS Repeated Parameter Request Denial of Service Vulnerability
The following example is available:
The following example is available:
Solution / Fix
Microsoft IIS Repeated Parameter Request Denial of Service Vulnerability
Solution:
The vendor released an advisory and updates. Please see the references for more information.
Microsoft IIS 7.0
Microsoft IIS 7.5
Microsoft IIS 5.1
Solution:
The vendor released an advisory and updates. Please see the references for more information.
Microsoft IIS 7.0
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB2124261)
http://www.microsoft.com/downloads/en/details.aspx?familyid=9864C590-1 0A7-4971-A717-924ED0D6CACE&displaylang=en -
Microsoft Security Update for Windows Server 2008 x64 Edition (KB2124261)
http://www.microsoft.com/downloads/en/details.aspx?familyid=E29F01DC-B 00D-4C12-A13E-63AA0B09D919&displaylang=en -
Microsoft Security Update for Windows Server 2008 (KB2124261)
http://www.microsoft.com/downloads/en/details.aspx?familyid=D798DC8E-A E64-4A1D-ABDA-F58CF69779D8&displaylang=en -
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB2124261)
http://www.microsoft.com/downloads/en/details.aspx?familyid=D595C8D2-9 0B1-46E4-BB9F-60EFD0BF3A02&displaylang=en -
Microsoft Security Update for Windows Vista (KB2124261)
http://www.microsoft.com/downloads/en/details.aspx?familyid=75059175-9 C59-45D5-81CE-09B964640E5F&displaylang=en
Microsoft IIS 7.5
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB2124261)
http://www.microsoft.com/downloads/en/details.aspx?familyid=66B64374-9 5E4-4B99-80E6-98DC63CD272B&displaylang=en -
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB2124261)
http://www.microsoft.com/downloads/en/details.aspx?familyid=3B8F3FD1-1 EF4-4E9F-9BCE-0C68F10519D1&displaylang=en -
Microsoft Security Update for Windows 7 (KB2124261)
http://www.microsoft.com/downloads/en/details.aspx?familyid=5B2D42DA-4 DBC-4FBB-BE22-09CA7DEC5AA3&displaylang=en -
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB2124261)
http://www.microsoft.com/downloads/en/details.aspx?familyid=21458CCE-F 67E-4E95-A067-8311AFEFC261&displaylang=en
Microsoft IIS 5.1
-
Microsoft Security Update for Windows XP (KB2124261)
http://www.microsoft.com/downloads/en/details.aspx?familyid=555864C3-9 114-4988-8526-7BF545A27706&displaylang=en
References
Microsoft IIS Repeated Parameter Request Denial of Service Vulnerability
References:
References: