First published: Wed Jul 07 1999(Updated: )
IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Server | =3.0 | |
Microsoft Internet Information Server | =4.0 | |
=3.0 | ||
=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1537 is classified as a denial of service vulnerability due to the resource exhaustion it can cause.
To mitigate CVE-1999-1537, ensure that SSL is only applied to pages that require encryption and consider upgrading to a more secure version of IIS.
CVE-1999-1537 affects Microsoft Internet Information Server versions 3.0 and 4.0.
CVE-1999-1537 can facilitate denial of service attacks via unsolicited SSL requests to unencrypted files.
A possible workaround for CVE-1999-1537 is to restrict access to the HTTPS port for files that do not require SSL.