Microsoft Internet Security and Acceleration Server Bugs Let Remote Users Poison the Cache and Establish NetBIOS Connections
|
|
SecurityTracker Alert ID: 1014193
|
|
SecurityTracker URL: http://securitytracker.com/id?1014193
|
|
CVE Reference: CVE-2005-1215
, CVE-2005-1216
(Links to External Site)
|
Updated: Aug 12 2008
|
Original Entry Date: Jun 14 2005
|
Impact: Modification of system information, Modification of user information, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Microsoft Security Advisory
|
Version(s): 2000 SP2
|
Description: Two vulnerabilities were reported in the Microsoft Internet Security and Acceleration (ISA) Server. A remote user can poison the cache. A remote user can also establish a NetBIOS connection to the ISA Server.
The server does not properly process HTTP content headers. A remote user can submit a specially crafted HTTP request to poison the
cache of the affected ISA server [CVE: CAN-2005-1215]. As a result, the remote user can access content that would otherwise have
been restricted by the server or to cause a target user to be directed to unexpected content.
A remote user can exploit a flaw
in the NetBIOS (all) predefined packet filter to establish a NetBIOS connection to the target ISA Server [CVE: CAN-2005-1216].
The
vendor credits Steve Orrin of Watchfire with reporting the HTTP content header vulnerability.
|
Impact: A remote user can poison the cache of the affected ISA server.
A remote user can establish a NetBIOS connection to services on the target ISA Server that use NetBIOS.
|
Solution: The vendor has issued the following fix:
Microsoft Internet Security and Acceleration (ISA) Server 2000 Service Pack 2:
http://www.microsoft.com/downloads/details.as
px?FamilyId=E579813B-0372-45BE-8070-3F4D7D4CB89C
A restart is not required.
|
Vendor URL: www.microsoft.com/technet/security/Bulletin/MS05-034.mspx (Links to External Site)
|
Cause: Access control error, Input validation error
|
Underlying OS: Windows (2000)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Tue, 14 Jun 2005 13:26:43 -0400
Subject: http://www.microsoft.com/technet/security/Bulletin/MS05-034.mspx
|
http://www.microsoft.com/technet/security/Bulletin/MS05-034.mspx
|
|