HTTP: IIS Malformed PROPFIND Remote DoS

This signature detects attempts to exploit a known vulnerability in Microsoft IIS 5.0. Attackers can send malicious "PROPFIND" requests to the server to crash it.

Extended Description

Microsoft Internet Information Services has been reported vulnerable to a denial of service. When WebDAV receives excessively long requests to the 'PROPFIND' or 'SEARCH' variables, the IIS service will fail. All current web, FTP, and email sessions will be terminated. IIS will automatically restart and normal service will resume. ** It has been reported that if a WebDAV request with a certain number of bytes is received, the Inetinfo service will remain alive but cease serving requests. This will cause the IIS server to stop serving requests until the service is manually restarted. This vulnerability was initially described in BID 7728 and is now being assigned its own BID.

Affected Products

Microsoft iis

Short Name
HTTP:IIS:PROPFIND
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2003-0226 DoS IIS Malformed PROPFIND Remote bid:7735
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Microsoft

CVSS Score

5.0

Found a potential security threat?