First published: Fri May 30 2003(Updated: )
The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services (IIS) | =5.0 | |
Microsoft Internet Information Services | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0225 is considered a denial of service vulnerability due to its potential for causing significant memory consumption.
To mitigate CVE-2003-0225, consider upgrading to a newer version of Internet Information Services that does not have this vulnerability.
CVE-2003-0225 affects Microsoft Internet Information Services (IIS) versions 4.0 and 5.0.
CVE-2003-0225 facilitates denial of service attacks by allowing attackers to send oversized headers.
Yes, CVE-2003-0225 can be exploited remotely by attackers who can send HTTP requests to the affected server.