1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. HTTP MS FrontPage SmartHTML DoS

HTTP MS FrontPage SmartHTML DoS

Severity: Medium

This attack could pose a moderate security threat. It does not require immediate action.

Description

This signature detects an attempt to conduct a Denial of Service against the SmartHTML Interpreter Frontpage Server Extension.

Additional Information

FrontPage Server Extensions are a component for FrontPage that allows authorized users to edit and maintain content.

FrontPage Server Extensions include the SmartHTML interpreter, which allows web pages to access various FrontPage features. A denial of service vulnerability has been reported in the SmartHTML interpreter that may be exploited by remote attackers. It is possible to send an invalid request that will cause the interpreter to cycle, denying availability of CPU resources. In this manner, it is possible to cause a denial of service by exhausting available resources on the system.

Affected

  • Microsoft FrontPage Server Extensions 2000
  • Microsoft FrontPage Server Extensions 2002
  • Microsoft SharePoint Team Services 2002
  • Microsoft Windows 2000 Advanced Server SP2, SP3
  • Microsoft Windows 2000 Datacenter Server SP2, SP3
  • Microsoft Windows 2000 Professional SP2, SP3
  • Microsoft Windows 2000 Server SP2, SP3
  • Microsoft Windows XP 64-bit Edition SP1
  • Microsoft Windows XP Home SP1
  • Microsoft Windows XP Professional SP1

Response

Microsoft has released updates to address this issue.

Microsoft FrontPage Server Extensions 2000:
Microsoft Upgrade Security Update for Microsoft FrontPage Server Extensions 2000
http://www.microsoft.com/downloads/details.aspx?FamilyId=C84C3D10-A821-4819-BF58-D3BC70A77BFA&displaylang=en

Microsoft FrontPage Server Extensions 2002:
Microsoft Upgrade FrontPage 2002 Server Extensions Security Patch: KB813380
http://www.microsoft.com/downloads/details.aspx?FamilyId=3E8A21D9-708E-4E69-8299-86C49321EE25&displaylang=en

Microsoft SharePoint Team Services 2002:
Microsoft Upgrade Office XP Web Services Security Patch: KB812708
http://www.microsoft.com/downloads/details.aspx?FamilyId=5923FC2F-D786-4E32-8F15-36A1C9E0A340&displaylang=en

Microsoft Windows 2000 Advanced Server SP2:
Microsoft Upgrade Security Update for Windows 2000: KB810217
http://www.microsoft.com/downloads/details.aspx?FamilyId=057D5F0E-0E2B-47D2-9F0F-3B15DD8622A2&displaylang=en

Microsoft Windows 2000 Advanced Server SP3:
Microsoft Upgrade Security Update for Windows 2000: KB810217
http://www.microsoft.com/downloads/details.aspx?FamilyId=057D5F0E-0E2B-47D2-9F0F-3B15DD8622A2&displaylang=en

Microsoft Windows 2000 Professional SP2:
Microsoft Upgrade Security Update for Windows 2000: KB810217
http://www.microsoft.com/downloads/details.aspx?FamilyId=057D5F0E-0E2B-47D2-9F0F-3B15DD8622A2&displaylang=en

Microsoft Windows 2000 Professional SP3:
Microsoft Upgrade Security Update for Windows 2000: KB810217
http://www.microsoft.com/downloads/details.aspx?FamilyId=057D5F0E-0E2B-47D2-9F0F-3B15DD8622A2&displaylang=en

Microsoft Windows 2000 Server SP2:
Microsoft Upgrade Security Update for Windows 2000: KB810217
http://www.microsoft.com/downloads/details.aspx?FamilyId=057D5F0E-0E2B-47D2-9F0F-3B15DD8622A2&displaylang=en

Microsoft Windows 2000 Server SP3:
Microsoft Upgrade Security Update for Windows 2000: KB810217
http://www.microsoft.com/downloads/details.aspx?FamilyId=057D5F0E-0E2B-47D2-9F0F-3B15DD8622A2&displaylang=en

Microsoft Windows XP Home SP1:
Microsoft Upgrade Security Update for Windows XP: KB810217
http://www.microsoft.com/downloads/details.aspx?FamilyId=9B302532-BFAB-489B-82DC-ED1E49A16E1C&displaylang=en

Microsoft Windows XP Professional SP1:
Microsoft Upgrade Security Update for Windows XP: KB810217
http://www.microsoft.com/downloads/details.aspx?FamilyId=9B302532-BFAB-489B-82DC-ED1E49A16E1C&displaylang=en
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube