Microsoft FrontPage PWS DoS Vulnerability
BID:568
Info
Microsoft FrontPage PWS DoS Vulnerability
| Bugtraq ID: | 568 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 08 1999 12:00AM |
| Updated: | Aug 08 1999 12:00AM |
| Credit: | Posted to Bugtraq on August 9, 1999 by Narr0w <[email protected]>. |
| Vulnerable: |
Microsoft FrontPage Personal WebServer 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft FrontPage PWS DoS Vulnerability
A 'GET' request for a URL longer than 166 characters will overflow a buffer and cause the web server to crash with the following or similar error message:
VHTTPD32 caused an invalid page fault in
module VHTTPD32.EXE at 0137:0040aaed.
Registers:
EAX=010d7740 CS=0137 EIP=0040aaed EFLGS=00010202
EBX=00000000 SS=013f ESP=010d53d0 EBP=010d0074
ECX=010d7740 DS=013f ESI=010d7740 FS=13c7
EDX=000000a8 ES=013f EDI=bff92ac1 GS=0000
Bytes at CS:EIP:
ff 75 10 56 68 94 01 00 00 eb 1c 68 00 24 40 00
Stack dump:
00000010 010d7740 00000000 00000000 00000000
00000000 00000000 00000000 00000000 00000000
00000000 00000000 00000000 00000000 00000000
00000000
A 'GET' request for a URL longer than 166 characters will overflow a buffer and cause the web server to crash with the following or similar error message:
VHTTPD32 caused an invalid page fault in
module VHTTPD32.EXE at 0137:0040aaed.
Registers:
EAX=010d7740 CS=0137 EIP=0040aaed EFLGS=00010202
EBX=00000000 SS=013f ESP=010d53d0 EBP=010d0074
ECX=010d7740 DS=013f ESI=010d7740 FS=13c7
EDX=000000a8 ES=013f EDI=bff92ac1 GS=0000
Bytes at CS:EIP:
ff 75 10 56 68 94 01 00 00 eb 1c 68 00 24 40 00
Stack dump:
00000010 010d7740 00000000 00000000 00000000
00000000 00000000 00000000 00000000 00000000
00000000 00000000 00000000 00000000 00000000
00000000
Exploit / POC
Microsoft FrontPage PWS DoS Vulnerability
This exploit sends a 167 character URL to the target.
This exploit sends a 167 character URL to the target.
Solution / Fix
Microsoft FrontPage PWS DoS Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Microsoft FrontPage PWS DoS Vulnerability
References:
References: