|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
Microsoft IIS contains a flaw that may allow a remote denial of service. The issue occurs when an attacker sends a URL request with a different length than the one specified in the request. This results in an access violation causing IIS to crash and must be restarted. This vulnerability only occurs when URL redirection has been enabled.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Denial of Service
Impact:
Loss of Availability
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.
|
|
Products |
|
IIS
 |
4.0 |
5.0 |
|
|
|
|
Credit |
- John Waters - Deloitte and Touche
- NSFocus Security Team - security
nsfocus.com - NSFocus Security
- Oded Horovitz - Entercept Security Technologies
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|