IIS / Site Server Multithread SSL Vulnerability
BID:852
Info
IIS / Site Server Multithread SSL Vulnerability
| Bugtraq ID: | 852 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 02 1999 12:00AM |
| Updated: | Dec 02 1999 12:00AM |
| Credit: | Reported to Microsoft by Wall Data. Publicized by Microsoft in Security Bulletin MS99-053, released Decemeber 2, 1999. |
| Vulnerable: |
Microsoft Site Server Commerce Edition 3.0 i386 Microsoft Site Server Commerce Edition 3.0 alpha Microsoft IIS 4.0 |
| Not Vulnerable: | |
Discussion
IIS / Site Server Multithread SSL Vulnerability
The SSL ISAPI filter that ships with IIS 4 is vulnerable to an error that could allow sensitive, normally encrypted information to be transmitted in plaintext to the client. The error is in the way that the filter handles simultaneous threads. Under heavy load conditions, a multi-threaded client application could cause the server to transmit one buffer of data unencrypted and then to terminate the connection.
While the data is sent only to the client machine, the risk is that an attacker sniffing the connection could also receive the plaintext content.
The SSL ISAPI filter that ships with IIS 4 is vulnerable to an error that could allow sensitive, normally encrypted information to be transmitted in plaintext to the client. The error is in the way that the filter handles simultaneous threads. Under heavy load conditions, a multi-threaded client application could cause the server to transmit one buffer of data unencrypted and then to terminate the connection.
While the data is sent only to the client machine, the risk is that an attacker sniffing the connection could also receive the plaintext content.
Exploit / POC
IIS / Site Server Multithread SSL Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IIS / Site Server Multithread SSL Vulnerability
Solution:
Microsoft has released a patch for this issue, available at:
x86:
http://www.microsoft.com/downloads/release.asp?ReleaseID=16186
Alpha:
http://www.microsoft.com/downloads/release.asp?ReleaseID=16187
Solution:
Microsoft has released a patch for this issue, available at:
x86:
http://www.microsoft.com/downloads/release.asp?ReleaseID=16186
Alpha:
http://www.microsoft.com/downloads/release.asp?ReleaseID=16187
References
IIS / Site Server Multithread SSL Vulnerability
References:
References: