Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
BID:4482
Info
Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
| Bugtraq ID: | 4482 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0073 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | This vulnerability was discovered by H D Moore. |
| Vulnerable: |
Microsoft IIS 5.1 Microsoft IIS 5.0 Microsoft IIS 4.0 Cisco Unity Server 2.4 Cisco Unity Server 2.3 Cisco Unity Server 2.2 Cisco Unity Server 2.1 Cisco Unity Server 2.0 Cisco Call Manager 3.2 Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Building Broadband Service Manager (BBSM) 5.1 Cisco Building Broadband Service Manager (BBSM) 5.0 Cisco Building Broadband Service Manager (BBSM) 4.5 Cisco Building Broadband Service Manager (BBSM) 4.4 Cisco Building Broadband Service Manager (BBSM) 4.3 Cisco Building Broadband Service Manager (BBSM) 4.2 Cisco Building Broadband Service Manager (BBSM) 4.0.1 |
| Not Vulnerable: | |
Discussion
Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
A vulnerability has been identified in the way Microsoft Internet Information Server's FTP service handles certain requests for transfer status.
The condition is present when a request is made for the FTP transfer status is made via the STAT command. A client issuing this command with a large number of file globbing characters as the argument may cause the service to crash.
On IIS 4.0 servers, the service must be manually restarted. On IIS 5.0 and 5.1 servers, the service will restart itself automatically.
A number of Cisco products are affected by this vulnerability, although this issue is not present in the Cisco products themselves.
A vulnerability has been identified in the way Microsoft Internet Information Server's FTP service handles certain requests for transfer status.
The condition is present when a request is made for the FTP transfer status is made via the STAT command. A client issuing this command with a large number of file globbing characters as the argument may cause the service to crash.
On IIS 4.0 servers, the service must be manually restarted. On IIS 5.0 and 5.1 servers, the service will restart itself automatically.
A number of Cisco products are affected by this vulnerability, although this issue is not present in the Cisco products themselves.
Exploit / POC
Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
Solution:
Microsoft has released a cumulative patch to address this issue and others.
There are reports of problems with the fixes for users who are running
Microsoft IIS Site Server. A hotfix to address problems caused as a side
effect of installing the cumulative patch has apparently been released by
Microsoft. Any users who have experienced difficulties as a result of
installing the cumulative patch are advised to contact Microsoft support
and request hotfix Q317815.
Users of Cisco Unity products and Cisco Building Broadband Service Manager 4.x/5.x are advised to apply Microsoft's cumulative patch.
Microsoft IIS 4.0
Microsoft IIS 5.1
Microsoft IIS 5.0
Cisco Unity Server 2.0
Cisco Unity Server 2.1
Cisco Unity Server 2.2
Cisco Unity Server 2.3
Cisco Unity Server 2.4
Cisco Call Manager 3.0
Cisco Call Manager 3.1
Cisco Call Manager 3.2
Cisco Building Broadband Service Manager (BBSM) 4.0.1
Cisco Building Broadband Service Manager (BBSM) 4.2
Cisco Building Broadband Service Manager (BBSM) 4.3
Cisco Building Broadband Service Manager (BBSM) 4.4
Cisco Building Broadband Service Manager (BBSM) 4.5
Cisco Building Broadband Service Manager (BBSM) 5.0
Cisco Building Broadband Service Manager (BBSM) 5.1
Solution:
Microsoft has released a cumulative patch to address this issue and others.
There are reports of problems with the fixes for users who are running
Microsoft IIS Site Server. A hotfix to address problems caused as a side
effect of installing the cumulative patch has apparently been released by
Microsoft. Any users who have experienced difficulties as a result of
installing the cumulative patch are advised to contact Microsoft support
and request hotfix Q317815.
Users of Cisco Unity products and Cisco Building Broadband Service Manager 4.x/5.x are advised to apply Microsoft's cumulative patch.
Microsoft IIS 4.0
-
Microsoft Q317636
Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package
http://www.microsoft.com/ntserver/terminalserver/downloads/critical/q3 17636/default.asp -
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe
Microsoft IIS 5.1
-
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Microsoft IIS 5.0
-
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Unity Server 2.0
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Unity Server 2.1
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Unity Server 2.2
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Unity Server 2.3
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Unity Server 2.4
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Call Manager 3.0
Cisco Call Manager 3.1
Cisco Call Manager 3.2
Cisco Building Broadband Service Manager (BBSM) 4.0.1
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 4.2
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 4.3
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 4.4
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 4.5
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 5.0
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
Cisco Building Broadband Service Manager (BBSM) 5.1
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe -
Microsoft Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q 319733_WXP_SP1_x86_ENU.exe
References
Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
References:
References:
- IIS FTP STAT DoS (CORE Security)
- Microsoft Security Bulletin MS02-018 (Microsoft)
- Q317636 Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package (Microsoft)
- Vulnerability Note VU#412203 (CERT/CC)