![]() |
Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | ||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.100952 |
Categoría: | FTP |
Título: | Microsoft IIS FTPd NLST stack overflow |
Resumen: | Microsoft IIS FTPd NLST stack overflow;; The Microsoft IIS FTPd service may be vulnerable to a stack overflow via the NLST command. On Microsoft IIS 5.x this vulnerability; can be used to gain remote SYSTEM level access, whilst on IIS 6.x it has been reported to result in a denial of service. Whilst it; can be triggered by authenticated users with write access to the FTP server, this check determines whether anonymous users have the; write access necessary to trigger it without authentication. |
Descripción: | Summary: Microsoft IIS FTPd NLST stack overflow The Microsoft IIS FTPd service may be vulnerable to a stack overflow via the NLST command. On Microsoft IIS 5.x this vulnerability can be used to gain remote SYSTEM level access, whilst on IIS 6.x it has been reported to result in a denial of service. Whilst it can be triggered by authenticated users with write access to the FTP server, this check determines whether anonymous users have the write access necessary to trigger it without authentication. Solution: We are not aware of a vendor approved solution at the current time. On the following platforms, we recommend you mitigate in the described manner: Microsoft IIS 5.x Microsoft IIS 6.x We recommend you mitigate in the following manner: Filter inbound traffic to 21/tcp to only known management hosts Consider removing directories writable by 'anonymous' CVSS Score: 9.0 CVSS Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-3023 BugTraq ID: 36189 http://www.securityfocus.com/bid/36189 Cert/CC Advisory: TA09-286A http://www.us-cert.gov/cas/techalerts/TA09-286A.html CERT/CC vulnerability note: VU#276653 http://www.kb.cert.org/vuls/id/276653 http://www.exploit-db.com/exploits/9541 http://www.exploit-db.com/exploits/9559 Microsoft Security Bulletin: MS09-053 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-053 Microsoft Knowledge Base article: 975191 http://support.microsoft.com/default.aspx?scid=kb;[LN];Q975191 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6080 http://www.vupen.com/english/advisories/2009/2481 |
Copyright | Copyright (C) 2009 Tim Brown |
Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |