Vulnerabilities > CVE-2013-1305 - Resource Management Errors vulnerability in Microsoft Windows 8, Windows RT and Windows Server 2012
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
COMPLETE Summary
HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 4 |
Common Weakness Enumeration (CWE)
Msbulletin
bulletin_id | MS13-039 |
bulletin_url | |
date | 2013-05-14T00:00:00 |
impact | Denial of Service |
knowledgebase_id | 2829254 |
knowledgebase_url | |
severity | Important |
title | Vulnerability in HTTP.sys Could Allow Denial of Service |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS13-039.NASL |
description | The version of Windows installed on the remote host is potentially affected by a denial of service vulnerability because the HTTP protocol stack (HTTP.sys) may improperly handle a malicious HTTP header, causing an infinite loop in the HTTP protocol. A remote, unauthenticated attacker could exploit this flaw by sending a specially crafted HTTP packet to the affected system, which could trigger the vulnerability. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 66414 |
published | 2013-05-15 |
reporter | This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/66414 |
title | MS13-039: Vulnerability in HTTP.sys Could Allow Denial of Service (2829254) |
code |
|
Oval
accepted | 2013-07-01T04:00:23.894-04:00 | ||||||||
class | vulnerability | ||||||||
contributors |
| ||||||||
definition_extensions |
| ||||||||
description | HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability." | ||||||||
family | windows | ||||||||
id | oval:org.mitre.oval:def:16088 | ||||||||
status | accepted | ||||||||
submitted | 2013-05-17T10:14:08 | ||||||||
title | Vulnerability in HTTP.sys could allow denial of service - MS13-039 | ||||||||
version | 43 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 59784 CVE(CAN) ID: CVE-2013-1305 Microsoft Windows是微软公司推出的一系列操作系统。 当 HTTP 协议堆栈 (HTTP.sys) 不正确地处理恶意 HTTP 标头时,Windows Server 2012 和 Windows 8 中存在一个拒绝服务漏洞。成功利用此漏洞的攻击者可能通过向受影响的 Windows 服务器或客户端发送特制 HTTP 标头在 HTTP 协议堆栈中触发一个无限循环。 0 Microsoft Windows Windows Server 2012 Microsoft Windows RT Microsoft Windows 8 临时解决方法: 如果您不能立刻安装补丁或者升级,建议您采取以下措施以降低威胁: * 在企业外围防火墙上禁用TCP端口80和443。 * 根据自身情况,可以禁用IIS服务。 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(MS13-039)以及相应补丁: MS13-039:Vulnerability in HTTP.sys Could Allow Denial of Service (2829254) 链接:http://technet.microsoft.com/security/bulletin/MS13-039 |
id | SSV:60799 |
last seen | 2017-11-19 |
modified | 2013-05-17 |
published | 2013-05-17 |
reporter | Root |
title | Microsoft Windows 'HTTP.sys'远程拒绝服务漏洞(CVE-2013-1305)(MS13-039) |