ID

VAR-200912-0322


CVE

CVE-2009-4445


TITLE

Microsoft IIS Vulnerability to create an empty file with an arbitrary extension

Trust: 0.8

sources: JVNDB: JVNDB-2009-005240

DESCRIPTION

Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications, allows remote attackers to create empty files with arbitrary extensions via a filename containing an initial extension followed by a : (colon) and a safe extension, as demonstrated by an upload of a .asp:.jpg file that results in creation of an empty .asp file, related to support for the NTFS Alternate Data Streams (ADS) filename syntax. NOTE: it could be argued that this is a vulnerability in the third-party product, not IIS, because the third-party product should be applying its extension restrictions to the portion of the filename before the colon. IIS is prone to a remote security vulnerability

Trust: 1.89

sources: NVD: CVE-2009-4445 // JVNDB: JVNDB-2009-005240 // BID: 79184

AFFECTED PRODUCTS

vendor:microsoftmodel:internet information servicesscope:lteversion:6.0

Trust: 1.0

vendor:microsoftmodel:iisscope: - version: -

Trust: 0.8

vendor:microsoftmodel:internet information servicesscope:eqversion:6.0

Trust: 0.6

vendor:microsoftmodel:iisscope:eqversion:5.0

Trust: 0.3

vendor:microsoftmodel:iis alphascope:eqversion:4.0

Trust: 0.3

vendor:microsoftmodel:iisscope:eqversion:1.0

Trust: 0.3

sources: BID: 79184 // JVNDB: JVNDB-2009-005240 // CNNVD: CNNVD-200912-382 // NVD: CVE-2009-4445

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-4445
value: MEDIUM

Trust: 1.0

NVD: CVE-2009-4445
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200912-382
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2009-4445
severity: MEDIUM
baseScore: 6.0
vectorString: AV:N/AC:M/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 6.8
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2009-005240 // CNNVD: CNNVD-200912-382 // NVD: CVE-2009-4445

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.8

sources: JVNDB: JVNDB-2009-005240 // NVD: CVE-2009-4445

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200912-382

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-200912-382

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-005240

PATCH

title:Internet Explorerurl:http://windows.microsoft.com/en-US/internet-explorer/products/ie/home

Trust: 0.8

sources: JVNDB: JVNDB-2009-005240

EXTERNAL IDS

db:NVDid:CVE-2009-4445

Trust: 2.7

db:SECTRACKid:1023387

Trust: 1.9

db:JVNDBid:JVNDB-2009-005240

Trust: 0.8

db:CNNVDid:CNNVD-200912-382

Trust: 0.6

db:XFid:55308

Trust: 0.3

db:BIDid:79184

Trust: 0.3

sources: BID: 79184 // JVNDB: JVNDB-2009-005240 // CNNVD: CNNVD-200912-382 // NVD: CVE-2009-4445

REFERENCES

url:http://soroush.secproject.com/downloadable/iis-semicolon-report.pdf

Trust: 1.9

url:http://securitytracker.com/id?1023387

Trust: 1.9

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/55308

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-4445

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-4445

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/55308

Trust: 0.3

sources: BID: 79184 // JVNDB: JVNDB-2009-005240 // CNNVD: CNNVD-200912-382 // NVD: CVE-2009-4445

CREDITS

Unknown

Trust: 0.3

sources: BID: 79184

SOURCES

db:BIDid:79184
db:JVNDBid:JVNDB-2009-005240
db:CNNVDid:CNNVD-200912-382
db:NVDid:CVE-2009-4445

LAST UPDATE DATE

2024-11-23T21:47:41.338000+00:00


SOURCES UPDATE DATE

db:BIDid:79184date:2009-12-29T00:00:00
db:JVNDBid:JVNDB-2009-005240date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200912-382date:2009-12-30T00:00:00
db:NVDid:CVE-2009-4445date:2024-11-21T01:09:39.810

SOURCES RELEASE DATE

db:BIDid:79184date:2009-12-29T00:00:00
db:JVNDBid:JVNDB-2009-005240date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200912-382date:2009-12-29T00:00:00
db:NVDid:CVE-2009-4445date:2009-12-29T21:00:24.453