Microsoft Site Server and CIS Cookie Caching Vulnerability
BID:625
Info
Microsoft Site Server and CIS Cookie Caching Vulnerability
| Bugtraq ID: | 625 |
| Class: | Race Condition Error |
| CVE: |
CVE-1999-0910 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | First publicized in Microsoft Security Bullettin MS99-035 released September 10, 1999. |
| Vulnerable: |
Microsoft Site Server Commerce Edition 3.0 i386 Microsoft Site Server Commerce Edition 3.0 alpha Microsoft Commercial Internet System 2.5 Microsoft Commercial Internet System 2.0 |
| Not Vulnerable: | |
Discussion
Microsoft Site Server and CIS Cookie Caching Vulnerability
Some versions of Site Server and Commercial Internet System will send pages that set a cookie without flagging the page with an expiration header. If a web proxy caches the page, the next user to access that page through the same proxy will receive the same Set Cookie header. The second and subsequent users to do so may view personal or private information belonging to the first user if the cookies are part of an authentication scheme.
Some versions of Site Server and Commercial Internet System will send pages that set a cookie without flagging the page with an expiration header. If a web proxy caches the page, the next user to access that page through the same proxy will receive the same Set Cookie header. The second and subsequent users to do so may view personal or private information belonging to the first user if the cookies are part of an authentication scheme.
Exploit / POC
Microsoft Site Server and CIS Cookie Caching Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Site Server and CIS Cookie Caching Vulnerability
Solution:
Microsoft has released a patch that fixes this issue. It is available at:
ftp://ftp.microsoft.com/bussys/sitesrv/sitesrv-public/fixes/usa/siteserver3/Hotfixes-PostSP2/ProxyCache/
Solution:
Microsoft has released a patch that fixes this issue. It is available at:
ftp://ftp.microsoft.com/bussys/sitesrv/sitesrv-public/fixes/usa/siteserver3/Hotfixes-PostSP2/ProxyCache/
References
Microsoft Site Server and CIS Cookie Caching Vulnerability
References:
References: