Overview
The Microsoft FrontPage Server Extensions contains a vulnerability that allows unauthenticated remote attackers to conduct denial of service attacks.
Description
Microsoft FrontPage Server Extensions (FPSE) is an optional set of tools that adds functionality to a web site. This functionality includes remote server administration, content updates, and a variety of site-specific tools such as searching support and form handling. According to MS03-051, FPSE is installed by default on Internet Information Server (IIS) 4.0, 5.0, and 5.1. The SmartHTML interpreter, a sub-component of FPSE, contains a denial of service vulnerability. According to Microsoft, a specially crafted request can cause the SmartHTML interpreter to enter a loop that will temporarily consume processor time and interrupt the normal operation of the server host. |
Impact
This vulnerability allows unauthenticated remote attackers to conduct denial of service attacks against affected hosts. |
Solution
Apply a patch from Microsoft |
Disable FrontPage Server Extensions
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This document was written by Jeffrey P. Lanza and is based upon information provided by Microsoft.
Other Information
CVE IDs: | CVE-2003-0824 |
Severity Metric: | 3.09 |
Date Public: | 2003-11-11 |
Date First Published: | 2003-11-14 |
Date Last Updated: | 2003-11-14 19:44 UTC |
Document Revision: | 8 |