Guest Connected: 54162   Bookmark Us     Contact Us  
Total Shareware
Currently Listed: 244,916 Applications


  Utilities - Patches and Updates

Link To Program

  Microsoft IIS 'Malformed Extension Data in URL' Vulnerability patch  -  Version  MS00-030

Microsoft has released a patch that eliminates a security vulnerability in Microsoft® Internet Information Server. The vulnerability could be used to slow the performance of an affected server, or temporarily stop it altogether. In compliance with RFC 2396, the algorithm in IIS that processes URLs has flexibility built in to allow it to process any arbitrary sequence of file extensions or subresource identifiers (referred to in the RFC as path_segments). By providing an URL that contains specially-malformed file extension information, a malicious user could misuse this flexibility in order to arbitrarily increase the work factor associated with parsing the URL. This could consume much or all of the CPU availability on the server and prevent useful work from being done. The vulnerability does not provide any capability to cause the server to fail, or to add, change or delete data on it. Likewise, it provides no capability to usurp administrative control of the web server. The slowdown would only last until the URL had been processed, at which point service would return to normal.

To link to this program use the html below (use text editor and check the exact syntax):

<a href="http://www.TotalShareware.com/LinkToItem.aspx?id=8900">View this program at www.TotalShareware.com</a>

This link will appear like:

View this program at www.TotalShareware.com