Affected Versions:
Microsoft IIS 7.5
Microsoft IIS 7.0
Microsoft IIS 6.0
Microsoft IIS 5.1 vulnerability description:
Bugtraq id: 43140
Cve id: CVE-2010-1899
Microsoft Internet Information Service (IIS) is a network information server that comes with Microsoft Windows, which includes the HTTP service function.
The script processing code in IIS has the stack overflow vulnerability when processing repeated parameter requests. Remote attackers can exploit this vulnerability by sending a special URI request to the ASP page of the website hosted by IIS, service crash. <* Reference
Http://secunia.com/advisories/41399/
Http://www.us-cert.gov/cas/techalerts/TA10-257A.html
Http://www.microsoft.com/technet/security/bulletin/MS10-065.mspx? Pf = true
*>
Temporary solution:
* Temporarily disable ASP on the IIS server.
Vendor patch:
Microsoft
---------
Microsoft has released a Security Bulletin (MS10-065) and patches for this:
MS10-065: Vulnerabilities in Microsoft Internet Information Services (IIS) cocould Allow Remote Code Execution (2267960)
Link: http://www.microsoft.com/technet/security/bulletin/MS10-065.mspx? Pf = true