Zero-friction vulnerability management platform

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

IIS 5.0 WebDav Memory Leakage

Information

Severity

Severity

Medium

Family

Family

Denial of Service

CVSSv2 Base

CVSSv2 Base

5.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

17 years ago

Modified

Modified

3 years ago

Summary

The WebDav extensions (httpext.dll) for Internet Information Server 5.0 contains a flaw that may allow a malicious user to consume all available memory on the target server by sending many requests using the LOCK method associated to a non existing filename. This concern not only IIS but the entire system since the flaw can potentially exhausts all system memory available.

Affected Software

Affected Software

Vulnerable systems: IIS 5.0 ( httpext.dll versions prior to 0.9.3940.21 ) Immune systems: IIS 5 SP2( httpext.dll version 0.9.3940.21)

Solution

Solution

Download Service Pack 2/hotfixes from Microsoft.

Common Vulnerabilities and Exposures (CVE)