ID

VAR-200705-0032


CVE

CVE-2007-2897


TITLE

Microsoft IIS 6.0 Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2007-003909

DESCRIPTION

Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physical access to execute arbitrary code after connecting a data stream to a device COM port; via requests for a URI containing a '/' immediately before and after the name of a DOS device, as demonstrated by the /AUX/.aspx URI, which bypasses a blacklist for DOS device requests. Microsoft Internet Information Services is prone to a security-bypass vulnerability. Remote attackers can exploit this issue to hang the application, denying service to legitimate users, or disclose sensitive information. Attackers with physical access to the system may be able to execute arbitrary code with the privileges of the application. Microsoft Internet Information Services 6.0 is vulnerable; other versions may also be affected

Trust: 1.89

sources: NVD: CVE-2007-2897 // JVNDB: JVNDB-2007-003909 // BID: 51527

AFFECTED PRODUCTS

vendor:microsoftmodel:internet information serverscope:eqversion:6.0

Trust: 1.6

vendor:microsoftmodel:iisscope:eqversion:6.0

Trust: 0.8

sources: JVNDB: JVNDB-2007-003909 // CNNVD: CNNVD-200705-542 // NVD: CVE-2007-2897

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-2897
value: HIGH

Trust: 1.0

NVD: CVE-2007-2897
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200705-542
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2007-2897
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2007-003909 // CNNVD: CNNVD-200705-542 // NVD: CVE-2007-2897

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2007-2897

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200705-542

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200705-542

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-003909

PATCH

title:Internet Information Servicesurl:http://www.microsoft.com/ja-jp/server-cloud/windows-server/internet-information-services-iis.aspx

Trust: 0.8

sources: JVNDB: JVNDB-2007-003909

EXTERNAL IDS

db:NVDid:CVE-2007-2897

Trust: 2.7

db:JVNDBid:JVNDB-2007-003909

Trust: 0.8

db:FULLDISCid:20070522 QUESTION REGARDING IIS 6.0 / IS THIS A DOS???

Trust: 0.6

db:FULLDISCid:20070523 RE: QUESTION REGARDING IIS 6.0 / IS THIS A DOS???

Trust: 0.6

db:XFid:34418

Trust: 0.6

db:CNNVDid:CNNVD-200705-542

Trust: 0.6

db:BIDid:51527

Trust: 0.3

sources: BID: 51527 // JVNDB: JVNDB-2007-003909 // CNNVD: CNNVD-200705-542 // NVD: CVE-2007-2897

REFERENCES

url:http://archives.neohapsis.com/archives/fulldisclosure/2007-05/0419.html

Trust: 1.9

url:http://seclists.org/fulldisclosure/2007/may/0378.html

Trust: 1.6

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/34418

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-2897

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-2897

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/34418

Trust: 0.6

url:http://www.microsoft.com/windowsserver2003/iis/default.mspx

Trust: 0.3

url:http://seclists.org/fulldisclosure/2007/may/378

Trust: 0.3

sources: BID: 51527 // JVNDB: JVNDB-2007-003909 // CNNVD: CNNVD-200705-542 // NVD: CVE-2007-2897

CREDITS

Kingcope, 3APA3A

Trust: 0.3

sources: BID: 51527

SOURCES

db:BIDid:51527
db:JVNDBid:JVNDB-2007-003909
db:CNNVDid:CNNVD-200705-542
db:NVDid:CVE-2007-2897

LAST UPDATE DATE

2024-11-23T22:54:05.106000+00:00


SOURCES UPDATE DATE

db:BIDid:51527date:2007-05-22T00:00:00
db:JVNDBid:JVNDB-2007-003909date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200705-542date:2007-06-12T00:00:00
db:NVDid:CVE-2007-2897date:2024-11-21T00:31:55.427

SOURCES RELEASE DATE

db:BIDid:51527date:2007-05-22T00:00:00
db:JVNDBid:JVNDB-2007-003909date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200705-542date:2007-05-30T00:00:00
db:NVDid:CVE-2007-2897date:2007-05-30T10:30:00