CERT-In Vulnerability Note
CIVN-2005-0120
Microsoft IIS Malformed URL Potential Denial of Service Vulnerability
Original Issue Date:December 26, 2005
Severity Rating: HIGH
Systems Affected
Microsoft Internet Information Server V5.1
Overview
A vulnerability has been found in Microsoft Internet Information Services IIS , which potentially can be exploited by malicious people to cause a DoS Denial of Service .
Description
A vulnerability exists in IIS due to an error in handling of certain malformed URL. This vulnerability can be exploited to cause the IIS service to crash. URLs containing "~0", "~1", "~2", "~3", "~4", "~5", "~6", "~7", "~8", or "~9" can lead to exploit this vulnerability.
Note : - Microsoft Internet Information Server V5.0 and Microsoft Internet Information Server 6.0 are not vulnerable.
Workaround
Block all incoming malicious characters or character sequences.
References
1.
http://secunia.com/advisories/18106/
2.
http://ingehenriksen.blogspot.co...soft-iis-remote-dos-dll-url.html
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|