2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2009-1536" ,
"sourceIdentifier" : "secure@microsoft.com" ,
"published" : "2009-08-12T17:30:00.547" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T01:02:42.993" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka \"Remote Unauthenticated Denial of Service in ASP.NET Vulnerability.\""
} ,
{
"lang" : "es" ,
"value" : "ASP.NET en Microsoft .NET Framework v2.0 SP1 y SP2 y v3.5 Gold y SP1, cuando ASP 2.0 es usado en modo integrado sobre IIS v7.0, no administra adecuadamente las peticiones de planificaci\u00f3n, lo que permite a atacantes remotos provocar una denegaci\u00f3n de servicio (parada de demonio) a trav\u00e9s de una serie de peticiones HTTP manipuladas, tambi\u00e9n conocida como \"Vulnerabilidad de denegaci\u00f3n de servicio remota no autenticada en ASP.NET\"."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:H/Au:N/C:N/I:N/A:P" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 2.6 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "HIGH" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "LOW" ,
"exploitabilityScore" : 4.9 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-20"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:.net_framework:2.0:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "F97EB992-2DC1-4E31-A298-072D8313130B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "42A6DF09-B8E1-414D-97E7-453566055279"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E039CE1F-B988-4741-AE2E-5B36E2AF9688"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:.net_framework:3.5:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "0C610747-93E5-4014-8ED2-47F333174832"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "32623D48-7000-4C7D-823F-7D2A9841D88C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3852BB02-47A1-40B3-8E32-8D8891A53114"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "3A04E39A-623E-45CA-A5FC-25DAA0F275A3"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://blogs.technet.com/srd/archive/2009/08/11/ms09-035-asp-net-denial-of-service-vulnerability.aspx" ,
"source" : "secure@microsoft.com" ,
"tags" : [
"Vendor Advisory"
]
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://osvdb.org/56905" ,
"source" : "secure@microsoft.com" ,
"tags" : [
"Broken Link"
]
} ,
{
"url" : "http://secunia.com/advisories/36127" ,
"source" : "secure@microsoft.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://www.securityfocus.com/bid/35985" ,
"source" : "secure@microsoft.com" ,
"tags" : [
"Patch" ,
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.securitytracker.com/id?1022715" ,
"source" : "secure@microsoft.com" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.us-cert.gov/cas/techalerts/TA09-223A.html" ,
"source" : "secure@microsoft.com" ,
"tags" : [
"Third Party Advisory" ,
"US Government Resource"
]
} ,
{
"url" : "http://www.vupen.com/english/advisories/2009/2231" ,
"source" : "secure@microsoft.com" ,
"tags" : [
"Permissions Required" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-036" ,
"source" : "secure@microsoft.com"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6393" ,
"source" : "secure@microsoft.com" ,
"tags" : [
"Third Party Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://blogs.technet.com/srd/archive/2009/08/11/ms09-035-asp-net-denial-of-service-vulnerability.aspx" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://osvdb.org/56905" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Broken Link"
]
} ,
{
"url" : "http://secunia.com/advisories/36127" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "http://www.securityfocus.com/bid/35985" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.securitytracker.com/id?1022715" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.us-cert.gov/cas/techalerts/TA09-223A.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"US Government Resource"
]
} ,
{
"url" : "http://www.vupen.com/english/advisories/2009/2231" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Permissions Required" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-036" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6393" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}