|
Microsoft IIS contains a flaw that may allow a remote attacker to exhaust the available memory and force it to restart. The issue is due to IIS not limiting the memory available for constructing headers to be returned to a web client. If an attacker uploaded a specially crafted ASP page that returned an overly large header to the requesting client, IIS will run out of memory.
|