[prev in list] [next in list] [prev in thread] [next in thread] 

List:       microsoft-security
Subject:    Microsoft Security Bulletin MS02-026: Unchecked Buffer in ASP.NET Worker Process (Q322289)
From:       "Microsoft" <0_32255_54E7114E-E5BE-4674-B252-C01C732E46EC_US () Newsletters ! Microso
Date:       2002-06-07 0:07:30
[Download RAW message or body]

-----BEGIN PGP SIGNED MESSAGE-----

- ----------------------------------------------------------------------
Title:      Unchecked Buffer in ASP.NET Worker Process (Q322289)
Date:       06 June 2002
Software:   .NET Framework
Impact:     Denial of service, potentially run code of attacker's
            choice
Max Risk:   Moderate
Bulletin:   MS02-026

Microsoft encourages customers to review the Security Bulletin at: 
http://www.microsoft.com/technet/security/bulletin/MS02-026.asp.
- ----------------------------------------------------------------------

Issue:
======
ASP.NET is a collection of technologies that help developers to
build web-based applications. Web-based applications, including
those built using ASP.NET, rely on HTTP to provide connectivity.
One characteristic of HTTP as a protocol is that it is stateless,
meaning that each page request from a user to a site is reckoned
an independent request. To compensate for this, ASP.NET provides
for session state management through a variety of modes. 

One of these modes is StateServer mode. This mode stores session
state information in a separate, running process. That process
can run on the same machine or a different machine from the
ASP.NET application. There is an unchecked buffer in one of the
routines that handles the processing of cookies in StateServer
mode. A security vulnerability results because it is possible
for an attacker to seek to exploit it by mounting a buffer
overrun attack. A successful attack could cause the ASP.NET
application to restart. As a result, all current users of
the web-based application would see their current session
restart and their current session information would be lost. 

The StateServer mode is not the default mode for session
state management in ASP.NET. ASP.NET applications using
StateServer mode that do not use cookies are not vulnerable. 


Mitigating Factors:
====================
 - StateServer mode is not the default mode for session state
   management in ASP.NET. That ASP.NET application would have
   to be specifically configured to use this mode. 
 - Even if an application was configured to use StateServer
   mode, it would only be at risk if it also used cookies.

Risk Rating:
============
 - Internet systems: Moderate
 - Intranet systems: Moderate
 - Client systems: None

Patch Availability:
===================
 - A patch is available to fix this vulnerability. Please read the 
   Security Bulletin at
   http://www.microsoft.com/technet/security/bulletin/ms02-026.asp
   for information on obtaining this patch.


- ---------------------------------------------------------------------

THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS 
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS
ALL 
WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE 
WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
IN NO EVENT 
SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY
DAMAGES 
WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL,
LOSS OF 
BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR
ITS 
SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME
STATES DO 
NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL
OR 
INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.

-----BEGIN PGP SIGNATURE-----
Version: PGP 7.1

iQEVAwUBPP6hA40ZSRQxA/UrAQHJaAf+IKjIB6EkJpDbQ1RlmUrSYMR/icCSHEoI
e/NVBcvx85jgUiD08ZxHukVjDjWRrVsfOrLcsIoYEbpwPynHdpqLYDCW2D+nVX8/
ksAcWUPqdtkoZcNp0o7eXnce6oshy43im+mPc0UwSQi89YOGEYGS3bnKpwRq+Kdm
jpWDo59ibCohxYRev6+02SbuEi7UxMFG9yhQaMmfUOrSvR5xLuwV0Lz0mdb6a7qW
9r+x0P1MIZbFc7jzHj5dVKpCzz2tMLEs2FQ8Yq87dnyXMqo6hrsEUpomBpnA2tz8
qPSenO8BNqSenCBaMH66NF1ndAvfwtoYqCNz/wyY+KHaEv8nFa/4uA==
=mFGj
-----END PGP SIGNATURE-----


*******************************************************************

You have received this e-mail bulletin because of your subscription to the Microsoft \
Product Security Notification Service.  For more information on this service, please \
visit http://www.microsoft.com/technet/security/notify.asp.  
To verify the digital signature on this bulletin, please download our PGP key at \
http://www.microsoft.com/technet/security/notify.asp.  
To unsubscribe from the Microsoft Security Notification Service, please visit the \
Microsoft Profile Center at http://register.microsoft.com/regsys/pic.asp   
If you do not wish to use Microsoft Passport, you can unsubscribe from the Microsoft \
Security Notification Service via email as described below: Send an email to \
unsubscribe to the Service by following these steps:  a. Send an e-mail to \
securrem@microsoft.com. The subject line and the message body are not used to process \
the subscription request, and can be anything you like.  b. Send the e-mail. 
c. You will receive a response, asking you to verify that you really want to cancel \
your subscription. Compose a reply, and put "OK" in the message body. (Without the \
quotes). Send the reply.  d. You will receive an e-mail telling you that your name \
has been removed from the subscriber list.  
For security-related information about Microsoft products, please visit the Microsoft \
Security Advisor web site at http://www.microsoft.com/security.


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic