Date: 16 August 2001
Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2001.347 -- Microsoft Security Bulletin MS01-044
15 August 2001 Cumulative Patch for IIS
16 August 2001
===========================================================================
AusCERT Security Bulletin Summary
---------------------------------
Product: IIS 4.0 and 5.0
Vendor: Microsoft
Operating System: Windows NT 4
Windows 2000
Impact: Administrator Compromise
Denial of Service
Access Required: Remote
- --------------------------BEGIN INCLUDED TEXT--------------------
- -----BEGIN PGP SIGNED MESSAGE-----
- - ----------------------------------------------------------------------
Title: 15 August 2001 Cumulative Patch for IIS
Date: 15 August 2001
Software: IIS 4.0 and 5.0
Impact: Five vulnerabilities resulting in either denial of
service or privilege elevation
Bulletin: MS01-044
Microsoft encourages customers to review the Security Bulletin at:
http://www.microsoft.com/technet/security/bulletin/MS01-044.asp.
- - ----------------------------------------------------------------------
Issue:
======
This patch is a cumulative patch that includes the functionality of
all security patches released to date for IIS 5.0, and all patches
released for IIS 4.0 since Windows NT(r) 4.0 Service Pack 5. A
complete listing of the patches superseded by this patch is provided
below, in the section titled "Additional information about this
patch". Before applying the patch, system administrators should take
note of the caveats discussed in the same section.
In addition to including all previously released security patches,
this patch also includes fixes for five newly discovered security
vulnerabilities affecting IIS 4.0 and 5.0:
- A denial of service vulnerability that could enable an attacker
to cause the IIS 4.0 service to fail, if URL redirection has
been enabled. The "Code Red" worm generates traffic that can in
some cases exploit this vulnerability, with the result that an
IIS 4.0 machine that wasn't susceptible to infection via the
worm could nevertheless have its service disrupted by the worm.
- A denial of service vulnerability that could enable an attacker
to temporarily disrupt service on an IIS 5.0 web server. WebDAV
doesn't correctly handle particular type of very long, invalid
request. Such a request would cause the IIS 5.0 service to fail;
by default, it would automatically restart.
- A denial of service vulnerability involving the way IIS 5.0
interprets content containing a particular type of invalid MIME
header. If an attacker placed content containing such a defect
onto a server and then requested it, the IIS 5.0 service would
be unable to serve any content until a spurious entry was removed
from the File Type table for the site.
- A buffer overrun vulnerability involving the code that performs
server-side include (SSI) directives. An attacker who had the
ability to place content onto a server could include a malformed
SSI directive that, when the content was processed, would result
in code of the attacker's choice running in Local System context.
- A privilege elevation vulnerability that results because of a flaw
in a table that IIS 5.0 consults when determining whether a
process
should in-process or out-of-process. IIS 5.0 contains a table that
lists the system files that should always run in-process. However,
the list provides the files using relative as well as absolute
addressing, with the result that any file whose name matched that
of a file on the list would run in-process.
In addition, this patch eliminates a side effect of the previous IIS
cumulative patch (discussed in the Caveats section of Microsoft
Security Bulletin MS01-026) by restoring proper functioning of
UPN-style logons via FTP and W3SVC.
Mitigating Factors:
====================
URL Redirection denial of service:
- This vulnerability only affects IIS 4.0. IIS 5.0 is not
affected.
- The vulnerability only occurs if URL redirection is enabled.
- The vulnerability does not provide any capability to compromise
data on the server or gain administrative control over it.
WebDAV request denial of service:
- The vulnerability only affects IIS 5.0. IIS 4.0 is not affected.
- The effect of an attack via this vulnerability would be temporary.
The server would automatically resume normal service as soon as
the malformed requests stopped arriving.
- The vulnerability does not provide an attacker with any capability
to carry out WebDAV requests.
- The vulnerability does not provide any capability to compromise
data on the server or gain administrative control over it.
MIME header denial of service:
- The vulnerability only affects IIS 5.0. IIS 4.0 is not affected.
- In order to exploit this vulnerability, the attacker would need
to have the ability to install content on the server. However,
by default, unprivileged users do not have this capability, and
best practices strongly recommend against granting it to untrusted
users.
SSI privilege elevation vulnerability:
- In order to exploit this vulnerability, the attacker would need
to have the ability to install content on the server. However,
by default, unprivileged users do not have this capability, and
best practices strongly recommend against granting it to untrusted
users.
System file listing privilege elevation vulnerability:
- The vulnerability only affects IIS 5.0. IIS 4.0 is not affected.
- In order to exploit this vulnerability, the attacker would need
to have the ability to install content on the server. However,
by default, unprivileged users do not have this capability, and
best practices strongly recommend against granting it to untrusted
users.
Patch Availability:
===================
- A patch is available to fix these vulnerabilities. Please read the
Security Bulletin
http://www.microsoft.com/technet/security/bulletin/ms01-044.asp
for information on obtaining this patch.
Acknowledgment:
===============
- John Waters of Deloitte and Touche for reporting the MIME type
denial of service vulnerability.
- The NSFocus Security Team (http://www.nsfocus.com) for reporting
the SSI privilege elevation vulnerability.
- Oded Horovitz of Entercept(tm) Security Technologies
(http://www.entercept.com) for reporting the system file listing
privilege elevation vulnerability.
- - ---------------------------------------------------------------------
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED
"AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL
WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT
SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY
DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL,
CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF
MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE
POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION
OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO
THE FOREGOING LIMITATION MAY NOT APPLY.
- -----BEGIN PGP SIGNATURE-----
Version: PGP 7.1
iQEVAwUBO3s01I0ZSRQxA/UrAQEEuAgArZwsII6st0LxXkCCj6Z02o5EaISfDYrY
5zURDIKDzvaBv6UnQR5DmXix35O7vhge5HLUweF2bhfk9gsi+wAgq7I/zP0UNBC0
rHGnCVwtylbnlsXtm/kjKbd/+9vHpsjvegvMtARBAQJEBde0DMZUvblqBSLOSi3/
JPB7oNQ0A/Jsx5dfGBC8Tb7In0A5RC1lSk5rjdGUcOhy6Lh1Hrp50xpzEHyAH6r5
ORFY6h2X4rY+/yLlfIefFL1FICMspDN6GoYXEWKhsxdJZPqXLr3VVUB1A4NyPhJ/
bQXfwqXNC4n0MOb8XIPpC2QtLinyD1+JrgK23L8eHTSx1ot5ouVEqQ==
=RVKU
- -----END PGP SIGNATURE-----
- --------------------------END INCLUDED TEXT--------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
This security bulletin is provided as a service to AusCERT's members. As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to use any or all of this information is
the responsibility of each user or organisation, and should be done so in
accordance with site policies and procedures.
NOTE: This is only the original release of the security bulletin. It may
not be updated when updates to the original are made. If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the original authors to ensure that the information is still current.
Contact information for the authors of the original document is included
in the Security Bulletin above. If you have any questions or need further
information, please contact them directly.
Previous advisories and external security bulletins can be retrieved from:
http://www.auscert.org.au/Information/advisories.html
If you believe that your system has been compromised, contact AusCERT or
your representative in FIRST (Forum of Incident Response and Security
Teams).
Internet Email: auscert@auscert.org.au
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for emergencies.
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
Comment: ftp://ftp.auscert.org.au/pub/auscert/AUSCERT_PGP.key
iQCVAwUBO3vgdyh9+71yA2DNAQGXMgP/dnHBHdNsVZZd/UpEzrTSSzFFoKMSevxb
ZjHuVXTxNxofCZrSltwq8ArU3gMtNJmJnxtoaswolXD/GC2cHNbiFPmcBrXpNy2Z
EmP8kih4DytQAGMPd1qChO5z4I9T85ywzJ9KANmul02OVVFrUO1WPcAwPGbCDTcP
sU73DCj94Us=
=W1oV
-----END PGP SIGNATURE-----
|