CERT-In Vulnerability Note
CIVN-2009-0107
Multiple Vulnerabilities in Microsoft IIS FTP Service
Original Issue Date:September 01, 2009
Severity Rating: MEDIUM
Systems Affected
- Microsoft Internet Information Server IIS 5.0
FTP Service 5.0 - Microsoft Internet Information Server IIS 5.1
FTP Service 5.1 - Microsoft Internet Information Server IIS 6.0
FTP Service 6.0 - Microsoft Internet Information Server IIS 7.0
FTP Service 6.0
Overview
Two vulnerabilities have been identified in Microsoft Internet Information Server IIS FTP Service , which could be exploited by a remote, authenticated attacker to execute arbitrary code and to create Denial of Service DoS condition on a vulnerable system.
Description
1. FTP Directory Listing Remote Denial of Service Vulnerability
(
CVE-2009-2521
)
This issue is caused by an error when processing directory listing command containing a wildcard that references a subdirectory, followed by a .. dot dot , i.e. "*" character and "../" sequences . A remote attacker could exploit this vulnerability to exhaust the stack and crash the affected server, creating a Denial of Service DoS condition.
2. FTP Server NLST Buffer Overflow Vulnerability
(
CVE-2009-3023
)
This issue is caused by a stack based buffer overflow error in the FTP service when processing an NLST NAME LIST command on a specially-named directory. This could allow an anonymous or authenticated remote attacker with write access to execute arbitrary code with SYSTEM privileges on systems running FTP Service with IIS 5.0 on Microsoft Windows 2000 Service Pack 4 or to crash an affected server on the systems running IIS 5.1 and IIS 6.0.
Workaround
- Do not allow FTP write access to anonymous users
- Do not allow FTP access to anonymous users
- Modify NTFS file system permissions to disallow directory creation by FTP users
- Upgrade to FTP Service 7.5 for IIS 7.0
- Disable the FTP Service
For detailed steps of these workarounds refer to Microsoft Security Bulletin MS09-053
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS09-053
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/advisory/975191.mspx
References
Microsoft
http://www.microsoft.com/technet/security/advisory/975191.mspx
http://support.microsoft.com/kb/975254
US-CERT
http://www.kb.cert.org/vuls/id/276653
VUPEN Security
http://www.vupen.com/english/advisories/2009/2481
http://www.vupen.com/english/advisories/2009/2542
G-SEC
http://blog.g-sec.lu/2009/09/iis-5-iis-6-ftp-vulnerability.html
SecurityTracker
http://securitytracker.com/alerts/2009/Aug/1022792.html
Secunia
http://secunia.com/advisories/36443
CVE Name
CVE-2009-2521
CVE-2009-3023
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|