| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.900944 |
| Kategorie: | Denial of Service |
| Titel: | Microsoft IIS FTP Server 'ls' Command DOS Vulnerability |
| Zusammenfassung: | Verify the vulnerability through LIST command |
| Beschreibung: | Overview: The host is running Microsoft IIS with FTP server and is prone to Denial of Service vulnerability. Vulnerability Insight: A stack consumption error occurs in the FTP server while processing crafted LIST command containing a wildcard that references a subdirectory followed by a .. (dot dot). Impact: Successful exploitation will allows remote authenticated users to crash the application leading to denial of service condition. Impact Level: Application Affected Software/OS: Microsoft Internet Information Services version 5.0 and 6.0 Fix: Upgrade to IIS version 7.5 http://www.iis.net/ References: http://www.microsoft.com/technet/security/advisory/975191.mspx http://archives.neohapsis.com/archives/fulldisclosure/2009-09/0040.html http://blogs.technet.com/msrc/archive/2009/09/01/microsoft-security-advisory-975191-released.aspx http://blogs.technet.com/msrc/archive/2009/09/03/microsoft-security-advisory-975191-revised.aspx |
| Querverweis: |
BugTraq ID: 36273 Common Vulnerability Exposure (CVE) ID: CVE-2009-2521 http://archives.neohapsis.com/archives/fulldisclosure/2009-09/0040.html Microsoft Security Bulletin: MS09-053 http://www.microsoft.com/technet/security/Bulletin/MS09-053.mspx Microsoft Knowledge Base article: 975191 http://support.microsoft.com/default.aspx?scid=kb;[LN];Q975191 Cert/CC Advisory: TA09-286A http://www.us-cert.gov/cas/techalerts/TA09-286A.html http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6508 |
| Copyright | Copyright (C) 2009 SecPod |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|