Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft ISA Server Redirect URI Handler Web Proxy Service Remote Denial Of Service Vulnerability

Microsoft Internet Security and Acceleration (ISA) Server web proxy service is reported prone to a remote denial of service vulnerability. The issue is reported to exist because ISA server may fail to terminate a redirect URI string with a NULL byte when copying the URI into a temporary buffer. As a result of this failure, a read operation performed on the temporary buffer will read beyond its bounds, potentially resulting in a read access violation in the W3proxy.exe executable.







 

Privacy Statement
Copyright 2009, SecurityFocus