The information in this article applies to:
SYMPTOMSWhen a Web site visitor requests a selected file mapping, the request is mapped to an appropriate DLL for processing the visitor's request. The appropriate DLL may include any Microsoft DLL or an installed third-party filter DLL. A problem currently exists in the Microsoft DLLs for handling an improperly formatted request that uses an HTR, STM, or IDC application mapping. There is the possibility that this problem could be exploited by a malicious Web user by sending an improperly formatted HTTP request to a Microsoft Internet Information Server (IIS) computer, which can result in the unstable operation of the Web server. WORKAROUND
Microsoft has provided a patch to correct this problem; however, additional steps can be used to prevent issues similar to this one from impacting any Microsoft IIS 4.0 computer. Selecting Check if file Exists in the script application mappings section of the ISM forces IIS 4.0 to check if the requested script exists or if the user has permission to the requested script. If not, the appropriate warning message is returned to the browser and the script engine is not invoked.
RESOLUTIONTo resolve this problem, obtain the latest service pack for Windows NT 4.0 or
the individual software update. For information on obtaining the
latest service pack, please go to:
-or- http://www.microsoft.com/support/supportnet/overview/overview.aspThis hotfix has been posted to the following Internet location as Extfixi.exe (x86) and Extfixa.exe (Alpha): ftp://ftp.microsoft.com/bussys/IIS/iis-public/fixes/usa/ext-fix/ STATUSMicrosoft has confirmed this to be a problem in Internet Information Server 4.0. This problem was first corrected in Windows NT 4.0 Service Pack 6. MORE INFORMATION
The effected application mappings are IDC, HTR, and STM. Please see the following Microsoft Security Bulletin (MS99-019) for more information related to this issue: Patch Available for "Malformed HTR Request" VulnerabilityFor additional security-related information about Microsoft products, please visit: http://www.microsoft.com/security Additional query words:
Keywords : NT4SP6Fix |
Last Reviewed: October 28, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |