PT-2005-2229 · Microsoft · Isa Server 2000
Steve Orrin
·
Published
2005-06-14
·
Updated
2018-10-12
·
CVE-2005-1215
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft ISA Server 2000
Description
The issue allows remote attackers to poison the cache or bypass content restriction policies. This is achieved by sending a malformed HTTP request packet that contains multiple Content-Length headers.
Recommendations
For Microsoft ISA Server 2000, consider restricting access to the server until a fix is available, and review the server's content restriction policies to minimize potential impact. As a temporary workaround, consider implementing additional validation on incoming HTTP request packets to detect and prevent those with multiple Content-Length headers.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Isa Server 2000