VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
VRDA-090901-001     ( CVE-2009-3023 )
Microsoft Internet Information Server (IIS) FTP server NLST stack buffer overflow
http://www.kb.cert.org/vuls/id/276653

The Microsoft IIS FTP server contains a stack buffer overflow in the handling of directory names, which may allow a remote, authenticated attacker to execute arbitrary code on a vulnerable system.




About This Analysis Information
Analysis Information Provider:
JPCERT/CC
First Published:
2009-09-01
Source Information Category:
Advisory, Alert
Last Updated:
2009-09-01




Affected Product Tags
cpe:/a:microsoft:iis:5.0     (Microsoft IIS 5.0)
cpe:/a:microsoft:iis:5.1     (Microsoft IIS 5.1)
cpe:/a:microsoft:iis:6.0     (Microsoft IIS 6.0)
 


Vulnerability Analysis Results
[Information Source Reliability] [?]
Low [?]

Medium [?]
X High [?]

[Impact Level] [?]
Low [?]

Low-Medium [?]
Medium-High [?]
X High [?]

[Access Required] [?]
Physical [?]

Local [?]
Non-routed [?]
X Routed [?]

[Authentication] [?]
Privileged [?]

X Standard [?]
Limited [?]
None or Unnecessary [?]

[User Interaction Required] [?]
Complex [?]

Simple [?]
X None [?]

[Technical Difficulty] [?]
High [?]

Medium-High [?]
Low-Medium [?]
Low [?]

[Availability of Remediation] [?]
Official Patch [?]

Official Workaround [?]
X Unofficial Patch [?]
None [?]

[Incident Activity] [?]
None [?]

X Exploit or PoC [?]
Activity Observed [?]

Alternatives
Common Vulnerabilities and Exposures (CVE) CVE-2009-3023
Buffer overflow in the FTP server in Microsoft IIS 5.0 and 6.0 allowsremote authenticated users to execute arbitrary code via a craftedNLST command that uses wildcards.








References
Microsoft セキュリティ アドバイザリ (975191) インターネット インフォメーション サービスの FTP サービスの脆弱性により、リモートでコードが実行される
マイクロソフトは Microsoft Internet Information Services (IIS) 5.0、Microsoft Internet Information Services (IIS) 5.1、Microsoft Internet Information Services (IIS) 6.0 の FTP サービスの脆弱性に関する新たな報告を調査中です。この脆弱性により、影響を受けるシステム上で FTP サービスを稼働させ、インターネットに接続している場合、リモートでコードが実行される可能性があります。





Copyright © 2009 JPCERT/CC All Rights Reserved.