First published: Wed Aug 11 1999(Updated: )
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Commercial Internet System | =2.0 | |
Microsoft Commercial Internet System | =2.5 | |
Microsoft Internet Information Services | =4.0 | |
Microsoft Site Server Commerce | =3.0-unknown |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0867 has been classified as a denial of service vulnerability in IIS 4.0.
To mitigate CVE-1999-0867, it is recommended to limit the number of simultaneous connections to the IIS server and properly configure HTTP request handling.
CVE-1999-0867 affects Microsoft Internet Information Server 4.0, Microsoft Commercial Internet System 2.0, 2.5, and Microsoft Site Server 3.0.
CVE-1999-0867 describes a denial of service attack that floods the server with HTTP requests containing malformed headers.
While CVE-1999-0867 is an older vulnerability, systems still running affected software could potentially be at risk if not properly managed.