Microsoft IIS ASP Header Denial Of Service Vulnerability
BID:7733
Info
Microsoft IIS ASP Header Denial Of Service Vulnerability
| Bugtraq ID: | 7733 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0225 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | This vulnerability was reported by Microsoft. |
| Vulnerable: |
Microsoft IIS 5.0 Microsoft IIS 4.0 |
| Not Vulnerable: |
Microsoft IIS 6.0 Microsoft IIS 5.1 |
Discussion
Microsoft IIS ASP Header Denial Of Service Vulnerability
Microsoft IIS is prone to a denial of service condition when overly large ASP headers are processed.
An attacker can exploit this vulnerability to execute a malicious ASP page that generates an overly large header that consumes all memory resources available to the vulnerable IIS process.
This vulnerability was initially described in BID 7728 and is now being assigned its own BID.
Microsoft IIS is prone to a denial of service condition when overly large ASP headers are processed.
An attacker can exploit this vulnerability to execute a malicious ASP page that generates an overly large header that consumes all memory resources available to the vulnerable IIS process.
This vulnerability was initially described in BID 7728 and is now being assigned its own BID.
Exploit / POC
Microsoft IIS ASP Header Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft IIS ASP Header Denial Of Service Vulnerability
Solution:
Patches available:
There is a dependency associated with this patch. It requires the patch from Microsoft Security Bulletin MS02-050 to be installed. If this patch is installed and MS02-050 is not present, client side certificates will be rejected. This functionality can be restored by installing the MS02-050 patch.
Microsoft IIS 4.0
Microsoft IIS 5.0
Solution:
Patches available:
There is a dependency associated with this patch. It requires the patch from Microsoft Security Bulletin MS02-050 to be installed. If this patch is installed and MS02-050 is not present, client side certificates will be rejected. This functionality can be restored by installing the MS02-050 patch.
Microsoft IIS 4.0
-
Microsoft Q811114
IIS 4.0 patch to be installed on systems running Windows NT 4.0 Service Pack 6a.
http://microsoft.com/downloads/details.aspx?FamilyId=1DBC1914-98E9-4DE D-ADBF-E9B374A1F79D&displaylang=en
Microsoft IIS 5.0
-
Microsoft Q811114
IIS 5.0 patch to be installed on systems running Windows 2000 Service Pack 2 or Service Pack 3.
http://microsoft.com/downloads/details.aspx?FamilyId=2F5D9852-4ADD-44F 8-8715-AC3D7D7D94BF&displaylang=en
References
Microsoft IIS ASP Header Denial Of Service Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-050 (Microsoft)
- Microsoft Security Bulletin MS03-018 (Microsoft)