Microsoft IIS ASP Server-Side Include Buffer Overflow Vulnerability
BID:4478
Info
Microsoft IIS ASP Server-Side Include Buffer Overflow Vulnerability
| Bugtraq ID: | 4478 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2002 12:00AM |
| Updated: | Apr 10 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Microsoft. |
| Vulnerable: |
Microsoft IIS 5.1 Microsoft IIS 5.0 Microsoft IIS 4.0 Cisco Unity Server 2.4 Cisco Unity Server 2.3 Cisco Unity Server 2.2 Cisco Unity Server 2.1 Cisco Unity Server 2.0 Cisco Call Manager 3.2 Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Building Broadband Service Manager (BBSM) 5.1 Cisco Building Broadband Service Manager (BBSM) 5.0 Cisco Building Broadband Service Manager (BBSM) 4.5 Cisco Building Broadband Service Manager (BBSM) 4.4 Cisco Building Broadband Service Manager (BBSM) 4.3 Cisco Building Broadband Service Manager (BBSM) 4.2 Cisco Building Broadband Service Manager (BBSM) 4.0.1 |
| Not Vulnerable: | |
Discussion
Microsoft IIS ASP Server-Side Include Buffer Overflow Vulnerability
A buffer overflow related to the processing of requested filenames that are to be included in file includes in ASP scripts has been reported for Microsoft IIS (Internet Information Services).
A condition exists that may allow for an existing bounds check on potentially user-supplied input to be bypassed, resulting in a potential buffer overflow. This condition affects IIS 4.0, IIS 5.0 and IIS 5.1. Exploitation requires that the attacker can influence when and how the file is included.
Exploitation of this vulnerability may result in a denial of service or allow for a remote attacker to execute arbitrary instructions on the victim host.
A number of Cisco products are affected by this vulnerability, although this issue is not present in the Cisco products themselves.
A buffer overflow related to the processing of requested filenames that are to be included in file includes in ASP scripts has been reported for Microsoft IIS (Internet Information Services).
A condition exists that may allow for an existing bounds check on potentially user-supplied input to be bypassed, resulting in a potential buffer overflow. This condition affects IIS 4.0, IIS 5.0 and IIS 5.1. Exploitation requires that the attacker can influence when and how the file is included.
Exploitation of this vulnerability may result in a denial of service or allow for a remote attacker to execute arbitrary instructions on the victim host.
A number of Cisco products are affected by this vulnerability, although this issue is not present in the Cisco products themselves.
Solution / Fix
Microsoft IIS ASP Server-Side Include Buffer Overflow Vulnerability
Solution:
Microsoft has released an IIS cumulative patch to address this issue and
others.
There are reports of problems with the fixes for users who are running Microsoft IIS Site Server. A hotfix to address problems caused as a side effect of installing the cumulative patch has apparently been released by Microsoft. Any users who have experienced difficulties as a result of installing the cumulative patch are advised to contact Microsoft support and request hotfix Q317815.
Users of Cisco Unity products and Cisco Building Broadband Service Manager 4.x/5.x are advised to apply Microsoft's cumulative patch.
Microsoft IIS 4.0
Microsoft IIS 5.1
Microsoft IIS 5.0
Cisco Unity Server 2.0
Cisco Unity Server 2.1
Cisco Unity Server 2.2
Cisco Unity Server 2.3
Cisco Unity Server 2.4
Cisco Call Manager 3.0
Cisco Call Manager 3.1
Cisco Call Manager 3.2
Cisco Building Broadband Service Manager (BBSM) 4.0.1
Cisco Building Broadband Service Manager (BBSM) 4.2
Cisco Building Broadband Service Manager (BBSM) 4.3
Cisco Building Broadband Service Manager (BBSM) 4.4
Cisco Building Broadband Service Manager (BBSM) 4.5
Cisco Building Broadband Service Manager (BBSM) 5.0
Cisco Building Broadband Service Manager (BBSM) 5.1
Solution:
Microsoft has released an IIS cumulative patch to address this issue and
others.
There are reports of problems with the fixes for users who are running Microsoft IIS Site Server. A hotfix to address problems caused as a side effect of installing the cumulative patch has apparently been released by Microsoft. Any users who have experienced difficulties as a result of installing the cumulative patch are advised to contact Microsoft support and request hotfix Q317815.
Users of Cisco Unity products and Cisco Building Broadband Service Manager 4.x/5.x are advised to apply Microsoft's cumulative patch.
Microsoft IIS 4.0
-
Microsoft Q317636
Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package
http://www.microsoft.com/ntserver/terminalserver/downloads/critical/q3 17636/default.asp -
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe
Microsoft IIS 5.1
-
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Microsoft IIS 5.0
-
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Unity Server 2.0
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Unity Server 2.1
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Unity Server 2.2
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Unity Server 2.3
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Unity Server 2.4
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Call Manager 3.0
Cisco Call Manager 3.1
Cisco Call Manager 3.2
Cisco Building Broadband Service Manager (BBSM) 4.0.1
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 4.2
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 4.3
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 4.4
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 4.5
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 5.0
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 5.1
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
References
Microsoft IIS ASP Server-Side Include Buffer Overflow Vulnerability
References:
References:
- IIS ASP Server-Side Include exploit (CORE Security)
- Microsoft Security Bulletin MS02-018 (Microsoft)
- Microsoft Technet Security (Microsoft)
- Q317636 Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package (Microsoft)
- Vulnerability Note VU#721963 (CERT/CC)