ID

VAR-199907-0036


CVE

CVE-1999-1537


TITLE

NT IIS SSL DoS Vulnerability

Trust: 0.9

sources: BID: 521 // CNNVD: CNNVD-199907-011

DESCRIPTION

IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL. NT Servers running IIS with SSL security enabled are susceptible to a DoS attack due to the server's inability to differentiate between pages that require SSL and those that don't. Therefore, by replacing the 'http' string in the URL with 'https' the server can be forced to encrypt any content in the web site, including high-bandwidth pages. An attacker could, with carefully planned https requests, drive the processor utilization to 100% resulting in extreme slowdown or even failure of the server

Trust: 1.17

sources: NVD: CVE-1999-1537 // BID: 521

AFFECTED PRODUCTS

vendor:microsoftmodel:internet information serverscope:eqversion:4.0

Trust: 1.6

vendor:microsoftmodel:internet information serverscope:eqversion:3.0

Trust: 1.6

vendor:microsoftmodel:iisscope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:iisscope:eqversion:3.0

Trust: 0.3

sources: BID: 521 // CNNVD: CNNVD-199907-011 // NVD: CVE-1999-1537

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-1999-1537
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-199907-011
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-1999-1537
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

sources: CNNVD: CNNVD-199907-011 // NVD: CVE-1999-1537

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-1999-1537

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-199907-011

TYPE

Design Error

Trust: 0.9

sources: BID: 521 // CNNVD: CNNVD-199907-011

EXTERNAL IDS

db:NVDid:CVE-1999-1537

Trust: 1.9

db:BIDid:521

Trust: 1.9

db:NTBUGTRAQid:19990707 SSL AND IIS.

Trust: 0.6

db:XFid:2352

Trust: 0.6

db:CNNVDid:CNNVD-199907-011

Trust: 0.6

sources: BID: 521 // CNNVD: CNNVD-199907-011 // NVD: CVE-1999-1537

REFERENCES

url:http://www.securityfocus.com/bid/521

Trust: 2.6

url:http://marc.info/?l=ntbugtraq&m=93138827329577&w=2

Trust: 2.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/2352

Trust: 2.0

url:http://xforce.iss.net/static/2352.php

Trust: 0.6

url:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93138827329577&w=2

Trust: 0.6

sources: CNNVD: CNNVD-199907-011 // NVD: CVE-1999-1537

CREDITS

Posted to NTbugtraq July 7, 1999 by Heather.Field (Exchange) <Heather.Field@DHCMAIL.COM>.

Trust: 0.9

sources: BID: 521 // CNNVD: CNNVD-199907-011

SOURCES

db:BIDid:521
db:CNNVDid:CNNVD-199907-011
db:NVDid:CVE-1999-1537

LAST UPDATE DATE

2024-11-22T22:57:23.748000+00:00


SOURCES UPDATE DATE

db:BIDid:521date:2009-07-11T00:56:00
db:CNNVDid:CNNVD-199907-011date:2005-05-13T00:00:00
db:NVDid:CVE-1999-1537date:2024-11-20T23:31:21.257

SOURCES RELEASE DATE

db:BIDid:521date:1999-07-07T00:00:00
db:CNNVDid:CNNVD-199907-011date:1999-07-07T00:00:00
db:NVDid:CVE-1999-1537date:1999-07-07T04:00:00