Microsoft ASP.NET StateServer Cookie Handling Buffer Overflow Vulnerability
BID:4958
Info
Microsoft ASP.NET StateServer Cookie Handling Buffer Overflow Vulnerability
| Bugtraq ID: | 4958 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2002 12:00AM |
| Updated: | Jun 06 2002 12:00AM |
| Credit: | First announced in Microsoft Security Bulletin MS02-026. |
| Vulnerable: |
Microsoft .NET Framework 1.0 SP1 Microsoft .NET Framework 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft ASP.NET StateServer Cookie Handling Buffer Overflow Vulnerability
Microsoft's ASP.NET is a collection of technology. ASP.NET supports a range of common HTTP tasks, including the ability to maintain session state through the usage of client cookies. This may be accomplished through the use of ASP.NET's StateServer mode, in which state information is stored in a separate server process.
The StateServer process suffers from a buffer overflow vulnerability when processing large cookie data. Exploitation may lead to a denial of service condition. It may be possible to execute arbitrary code as the server process, this has not however been confirmed.
Microsoft's ASP.NET is a collection of technology. ASP.NET supports a range of common HTTP tasks, including the ability to maintain session state through the usage of client cookies. This may be accomplished through the use of ASP.NET's StateServer mode, in which state information is stored in a separate server process.
The StateServer process suffers from a buffer overflow vulnerability when processing large cookie data. Exploitation may lead to a denial of service condition. It may be possible to execute arbitrary code as the server process, this has not however been confirmed.
Exploit / POC
Microsoft ASP.NET StateServer Cookie Handling Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft ASP.NET StateServer Cookie Handling Buffer Overflow Vulnerability
Solution:
A patch is available from Microsoft for .NET Framework 1.0 SP1. This fix will be included in SP2.
Microsoft has advised ensuring that VS.NET is closed prior to manually installing any available patch.
Patches available:
Microsoft .NET Framework 1.0 SP1
Solution:
A patch is available from Microsoft for .NET Framework 1.0 SP1. This fix will be included in SP2.
Microsoft has advised ensuring that VS.NET is closed prior to manually installing any available patch.
Patches available:
Microsoft .NET Framework 1.0 SP1
-
Microsoft Q322289
To be applied to Microsoft .NET Framework 1.0 SP1.
http://download.microsoft.com/download/NETFrameworkRedistributable/Pat ch/1/NT45XP/EN-US/NDP10_QFEM_Q322289_En.exe