56905 : Microsoft .NET Framework Request Scheduling Crafted HTTP Request Remote DoS
Printer | http://osvdb.org/56905 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
9 1767 over 2 years ago about 1 year ago 10 times 100%

Timeline

Disclosure Date Vendor Solution Date
2009-08-11 2009-08-11

Description

.NET Framework contains a flaw that may allow a remote denial of service. The issue is triggered by the way ASP.NET scheduling is managed , and will result in loss of availability for the IIS service.

Classification

Location: Remote / Network Access
Attack Type: Denial of Service, Input Manipulation
Impact: Loss of Availability
Solution: Patch / RCS
Exploit: Exploit Rumored
Disclosure: Vendor Verified
OSVDB: Web Related

Technical

This vulnerability appears dependent on IIS 7.0 configured to use Integrated Authentication running in combination with the .NET Framework 2.0.

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft Corporation has released a patch to address this vulnerability.

Products

Microsoft Corporation
Watch-list
.NET Framework
Watch-list
2.0 Service Pack 2

References

Tools & Filters

40555
5128

Credit

CVSSv2 Score

CVSSv2 Base Score = 2.6
Source: nvd.nist.gov | Generated: 2009-08-12 | Disagree?

Access_vector_2 Access_complexity_0 Authentication_2 Confidentiality_impact_0 Integrity_impact_0 Availability_impact_1

Blogs

This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.

2009/08/11 20:37:21 | August Microsoft Patch Tuesday Roundup

from: Rapid7 Network Security Blog

Sheldon here again, with a quick summary of this month’s Microsoft Security updates … 9 advisories, with 19 vulnerabilities covered. Here’s the breakdown: MS09-036: Rated Important. Potential Denial of Service in ASP.NET in Microsoft Vista and 2008, covering 1 vulnerability: CVE-2009-1536. Important to note that this vulnerability only affects systems where IIS 7.0 is installed and ASP.NET [...]

2009/08/14 12:00:00 | MS09-036: Description of the ASP.NET security update for the Microsoft .NET Framework 3.5 and the Microsoft .NET Framework 2.0 Service Pack 1 on Windows Vista: August 11, 2009

from: DotNetSlackers Latest ASP.NET News

972591 ... MS09-036: Description of the ASP.NET security update for the Microsoft .NET Framework 3.5 and the Microsoft .NET Framework 2.0 Service Pack 1 on Windows Vista: August 11, 2009This RSS feed provided by kbAlerz.com.Visit kbAlertz.com to subscribe. It's 100% free and you'll be able to recieve e-mail or RSS updates for the technologies you pick from the Microsoft Knowledge Base.... Did you know that DotNetSlackers also publishes .net articles written by top known .net Authors? We already have over 80 articles in several categories including Silverlight.

2009/08/14 12:00:00 | MS09-036: Description of the ASP.NET security update for Microsoft .NET Framework 3.5 and Microsoft .NET Framework 2.0 Service Pack 1 on Windows Vista Service Pack 1 and on Windows Server 2008: August 11, 2009

from: DotNetSlackers Latest ASP.NET News

972593 ... MS09-036: Description of the ASP.NET security update for Microsoft .NET Framework 3.5 and Microsoft .NET Framework 2.0 Service Pack 1 on Windows Vista Service Pack 1 and on Windows Server 2008: August 11, 2009This RSS feed provided by kbAlerz.com.Visit kbAlertz.com to subscribe. It's 100% free and you'll be able to recieve e-mail or RSS updates for the technologies you pick from the Microsoft Knowledge Base....

2009/08/12 06:12:00 | VRT: Microsoft Tuesday Coverage for August 2009

from: Windows 2008 Security

Well, first Microsoft Tuesday after DefCon and as punishment, there are 9 advisories to note with 8 of them being suitable for detection by an IPS/IDS. Microsoft Security Advisory (MS09-036): Microsoft Internet Information Server (IIS) … See original here:  VRT: Microsoft Tuesday Coverage for August 2009

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use