First published: Wed Aug 11 1999(Updated: )
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Site Server Commerce | =3.0 | |
Microsoft Commercial Internet System | =2.0 | |
Microsoft Internet Information Services | =4.0 | |
Microsoft Commercial Internet System | =2.5 | |
Microsoft Commerce Server | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0861 is classified as a medium severity vulnerability due to potential information leakage.
To mitigate CVE-1999-0861, apply the latest security patches provided by Microsoft for affected versions of their products.
CVE-1999-0861 affects Microsoft Internet Information Server 4.0, Microsoft Site Server 3.0, and Microsoft Commercial Internet System versions 2.0 and 2.5.
The impact of CVE-1999-0861 is that it may allow unauthorized access to information in plaintext during SSL operations.
Disabling the SSL ISAPI filter can serve as a temporary workaround for CVE-1999-0861 until a patch is applied.