Bugtraq mailing list archives

Summary of MS00-100


From: Ben Greenbaum <bgreenbaum () SECURITYFOCUS COM>
Date: Wed, 27 Dec 2000 17:31:47 -0800

bugtraq id      2144
remote          Yes
local           Yes
published       December 22, 2000
updated         December 22, 2000
vulnerable      Microsoft IIS 5.0
                    + Microsoft Windows NT 2000
                Microsoft IIS 4.0
                    - Microsoft Windows NT 4.0
                    + Microsoft BackOffice 4.5
                       - Microsoft Windows NT 4.0
                    + Microsoft BackOffice 4.0
                       - Microsoft Windows NT 4.0

Description:
Microsoft IIS ships with Front Page Server Extensions (FPSE) which
enables administrators remote and local web page and content
management. Browse - time support is another feature within FPSE
which provides users with functional web applications.

Due to the way FPSE handles the processing of web forms, IIS is
subject to a denial of service. By supplying malformed data to one of the
FPSE functions IIS will stop responding. A restart of the service is
required in order to gain normal functionality.

It should be noted that the victim only requires to have FPSE installed
on the web server to be vulnerable.

Solution:
Microsoft has released a patch which addresses this issue:

 Microsoft IIS 5.0:

      Microsoft patch Q280322_W2K_SP2_x86_en

http://download.microsoft.com/download/win2000platform/Patch/q280322/NT5/EN-US/Q280322_W2K_SP2_x86_en.EXE

 Microsoft IIS 4.0:

      Microsoft patch Q280322i

http://download.microsoft.com/download/winntsrv40/Patch/q280322/NT4/EN-US/Q280322i.EXE

credit:
      Discovered by eEye Digital Security <http://www.eEye.com>
      and posted in a Microsoft Security Bulletin (MS00-100) on
      Dec 22, 2000.

reference:
web page:       Microsoft Security Bulletin (MS00-100)
http://www.microsoft.com/technet/security/bulletin/ms00-100.asp

web page:       Microsoft Security Bulletin (MS00-100): FAQ
http://www.microsoft.com/technet/security/bulletin/fq00-100.asp



Ben Greenbaum
Director of Site Content
SecurityFocus
http://www.securityfocus.com


Current thread: