=====================================================================
                                   CERT-Renater

                        Note d'Information No. 2009/VULN335
_____________________________________________________________________

DATE                      : 13/08/2009

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Windows 2000 Server, Windows Server 2008
                                running Microsoft .NET Framework.

======================================================================
KB970957
http://www.microsoft.com/technet/security/bulletin/MS09-036.mspx
______________________________________________________________________

Microsoft Security Bulletin MS09-036 - Important

Vulnerability in ASP.NET in Microsoft Windows Could Allow Denial of Service
(970957)

   Published: August 11, 2009

   Version: 1.0

General Information

Executive Summary

   This security update addresses a privately reported Denial of Service
   vulnerability in the Microsoft .NET Framework component of Microsoft
   Windows. This vulnerability can be exploited only when Internet
   Information Services (IIS) 7.0 is installed and ASP.NET is configured
   to use integrated mode on affected versions of Microsoft Windows. An
   attacker could create specially crafted anonymous HTTP requests that
   could cause the affected Web server to become non-responsive until the
   associated application pool is restarted. Customers who are running
   IIS 7.0 application pools in classic mode are not affected by this
   vulnerability.

   This security update is rated Important for all affected versions of
   Microsoft Windows. For more information, see the subsection, Affected
   and Non-Affected Software, in this section.

   The security update addresses the vulnerability by changing the way
   ASP.NET manages request scheduling. For more information about the
   vulnerability, see the Frequently Asked Questions (FAQ) subsection for
   the specific vulnerability entry under the next section, Vulnerability
   Information.

   Recommendation.  The majority of customers have automatic updating
   enabled and will not need to take any action because this security
   update will be downloaded and installed automatically. Customers who
   have not enabled automatic updating need to check for updates and
   install this update manually. For information about specific
   configuration options in automatic updating, see Microsoft
   Knowledge Base Article 294871.

   For administrators and enterprise installations, or end users who want
   to install this security update manually, Microsoft recommends that
   customers apply the update at the earliest opportunity using update
   management software, or by checking for updates using the
   Microsoft Update service.

Affected Software

   Microsoft .NET Framework 2.0 Service Pack 1
   Microsoft .NET Framework 3.5 (KB972593)
   Microsoft .NET Framework 2.0 Service Pack 2
   Microsoft .NET Framework 3.5 Service Pack 1 (KB972594)

Vulnerability Information

Remote Unauthenticated Denial of Service in ASP.NET Vulnerability -
CVE-2009-1536

   A Denial of Service vulnerability exists in the way ASP.NET manages
   request scheduling. An attacker could exploit this vulnerability by
   creating specially crafted anonymous HTTP requests that would cause
   the affected Web server to become non-responsive until the associated
   application pool is restarted.


======================================================================

          =========================================================
          Les serveurs de référence du CERT-Renater
          http://www.urec.fr/securite
          http://www.cru.fr/securite
          http://www.renater.fr
          =========================================================
          + CERT-RENATER          | tel : 01-53-94-20-44          +
          + 151 bd de l'Hopital   | fax : 01-53-94-20-41          +
          + 75013 Paris           | email: certsvp@renater.fr     +
          =========================================================

