CVE-1999-0012: High severity Microsoft FrontPage vulnerability
Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable or configure the web server's request-filtering or URL/path normalization features to reject or normalize requests that contain excessively long file names or path segments, preventing access-control bypass via long file names.
Microsoft Internet Information Services; Microsoft Office FrontPage; Microsoft Personal Web Server; Netscape Enterprise Server; Netscape FastTrack Server request filename length handling / request filtering = enable rejection or normalization of requests with excessively long file names - Compensating control
Deploy WAF, reverse-proxy, or perimeter firewall rules to detect and block HTTP requests containing excessively long file names or path segments. Restrict external access to the affected web servers to trusted networks or IP addresses until vendor fixes are available.
- Operational
Audit web server logs for requests containing long file names, investigate any such requests for possible unauthorized access, and verify and correct filesystem and web-access permissions for files with long names to ensure access restrictions are enforced.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0012?
CVE-1999-0012 is considered a moderate severity vulnerability as it allows remote attackers to bypass access restrictions.
How do I fix CVE-1999-0012?
To fix CVE-1999-0012, ensure that your web server is updated to the latest version and review the configuration for proper file access restrictions.
Which software is affected by CVE-1999-0012?
CVE-1999-0012 affects Microsoft Office FrontPage, Microsoft Internet Information Server 4.0, Microsoft Personal Web Server 4.0, and specific versions of Netscape servers.
What is the impact of CVE-1999-0012?
The impact of CVE-1999-0012 allows attackers to access restricted files, potentially leading to data exposure or unauthorized actions.
Who is at risk from CVE-1999-0012?
Web servers running the affected software versions are at risk from CVE-1999-0012, especially if not properly configured.