Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.802440
Kategorie:Windows : Microsoft Bulletins
Titel:Microsoft IIS FTP Server 'Malformed FTP List Request' DOS Vulnerability
Zusammenfassung:This host is missing important security update according to; Microsoft Bulletin MS99-033.
Beschreibung:Summary:
This host is missing important security update according to
Microsoft Bulletin MS99-033.

Vulnerability Insight:
The FTP service in IIS has an unchecked buffer in a component that processes
'list' commands. A constructed 'list' request could cause arbitrary code to
execute on the server via a classic buffer overrun technique.

Vulnerability Impact:
Successful exploitation will allow remote users to crash the application
leading to denial of service condition or execute arbitrary code.

Affected Software/OS:
Microsoft Internet Information Services version 3.0 and 4.0.

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: BugTraq ID: 192
Common Vulnerability Exposure (CVE) ID: CVE-1999-0349
Bugtraq: Jan27,1999 (Google Search)
eEye Security Advisory: IIS Remote FTP Exploit/DoS Attack
http://www.eeye.com/html/Research/Advisories/IIS%20Remote%20FTP%20Exploit/DoS%20Attack.html
Microsoft Security Bulletin: MS99-003
https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-003
Microsoft Knowledge Base article: Q188348
http://support.microsoft.com/default.aspx?scid=kb;[LN];Q188348
XForce ISS Database: iis-remote-ftp
CopyrightCopyright (C) 2012 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.