Vulnerability Bulletins |
Desbordamiento de búfer en servidor FTP de Microsoft ISS |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Obtener acceso |
| Dificulty | Principiante |
| Required attacker level | Acceso remoto con cuenta |
System information |
|
| Property | Value |
| Affected manufacturer | Microsoft |
| Affected software | Servidor FTP de Microsoft Internet Information Server (IIS) 5 y 6 |
Description |
|
|
Se ha descubierto una vulnerabilidad de tipo desbordamiento de búfer en el servidor FTP de Microsoft Internet Information Server (IIS). Un atacante remoto autenticado podría ejecutar comandos arbitrarios mediante un comando NLST especialmente diseñado. Exploit público disponible. |
|
Solution |
|
|
Actualización de software Microsoft Actualmente no existe ningún parche disponible. |
|
Standar resources |
|
| Property | Value |
| CVE | CVE-2009-3023 |
| BID | 36189 |
Other resources |
|
|
Microsoft Security Advisory (975191) http://www.microsoft.com/technet/security/advisory/975191.mspx |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2009-09-03 |






