Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.100952
Kategorie:FTP
Titel:Microsoft IIS FTPd NLST stack overflow
Zusammenfassung:Microsoft IIS FTPd NLST stack overflow;; The Microsoft IIS FTPd service may be vulnerable to a stack overflow via the NLST command. On Microsoft IIS 5.x this vulnerability; can be used to gain remote SYSTEM level access, whilst on IIS 6.x it has been reported to result in a denial of service. Whilst it; can be triggered by authenticated users with write access to the FTP server, this check determines whether anonymous users have the; write access necessary to trigger it without authentication.
Beschreibung:Summary:
Microsoft IIS FTPd NLST stack overflow

The Microsoft IIS FTPd service may be vulnerable to a stack overflow via the NLST command. On Microsoft IIS 5.x this vulnerability
can be used to gain remote SYSTEM level access, whilst on IIS 6.x it has been reported to result in a denial of service. Whilst it
can be triggered by authenticated users with write access to the FTP server, this check determines whether anonymous users have the
write access necessary to trigger it without authentication.

Solution:
We are not aware of a vendor approved solution at the current time.

On the following platforms, we recommend you mitigate in the described manner:

Microsoft IIS 5.x

Microsoft IIS 6.x

We recommend you mitigate in the following manner:

Filter inbound traffic to 21/tcp to only known management hosts
Consider removing directories writable by 'anonymous'

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-3023
BugTraq ID: 36189
http://www.securityfocus.com/bid/36189
Cert/CC Advisory: TA09-286A
http://www.us-cert.gov/cas/techalerts/TA09-286A.html
CERT/CC vulnerability note: VU#276653
http://www.kb.cert.org/vuls/id/276653
http://www.exploit-db.com/exploits/9541
http://www.exploit-db.com/exploits/9559
Microsoft Security Bulletin: MS09-053
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-053
Microsoft Knowledge Base article: 975191
http://support.microsoft.com/default.aspx?scid=kb;[LN];Q975191
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6080
http://www.vupen.com/english/advisories/2009/2481
CopyrightCopyright (C) 2009 Tim Brown

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.