CVE-1999-1537
Internet Information Server 3.x-4.x - Denial of Service via SSL Requests to HTTPS Port
Title source: llmDescription
IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.
References (3)
Core 3
Core References
Mailing List mailing-list
x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=93138827329577&w=2
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/521
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/2352
Scores
EPSS
0.0853
EPSS Percentile
94.5%
Details
Status
published
Products (2)
microsoft/internet_information_server
3.0
microsoft/internet_information_server
4.0
Published
Jul 07, 1999
Tracked Since
Feb 18, 2026