Vulnerabilities > CVE-2003-0225 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS03-018.NASL |
description | The remote host is running a version of IIS that contains various flaws that could allow remote attackers to disable this service remotely and local attackers (or remote attackers with the ability to upload arbitrary files on this server) to gain SYSTEM level access on this host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11683 |
published | 2003-06-02 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11683 |
title | MS03-018: Cumulative Patch for Internet Information Services (11114) |
code |
|
Oval
accepted | 2011-05-16T04:02:51.794-04:00 | ||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||
contributors |
| ||||||||||||||||||||
description | The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page. | ||||||||||||||||||||
family | windows | ||||||||||||||||||||
id | oval:org.mitre.oval:def:373 | ||||||||||||||||||||
status | accepted | ||||||||||||||||||||
submitted | 2003-10-10T12:00:00.000-04:00 | ||||||||||||||||||||
title | IIS AddHeader Large Header Denial of Service | ||||||||||||||||||||
version | 32 |
References
- http://marc.info/?l=ntbugtraq&m=105110606122772&w=2
- http://marc.info/?l=ntbugtraq&m=105110606122772&w=2
- http://www.aqtronix.com/Advisories/AQ-2003-01.txt
- http://www.aqtronix.com/Advisories/AQ-2003-01.txt
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A373
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A373