CVE-2014-0253 Information
Feb 14, 2021
cve
Description
Microsoft .NET Framework 1.1 SP1 2.0 SP2 3.5 3.5.1 4 4.5 and 4.5.1 does not properly determine TCP connection states which allows remote attackers to cause a denial of service (ASP.NET daemon hang) via crafted HTTP requests that trigger persistent resource consumption for a (1) stale or (2) closed connection as exploited in the wild in February 2014 aka \POST Request DoS Vulnerability.\
Reference
http://osvdb.org/103162 http://secunia.com/advisories/56793 http://www.securityfocus.com/bid/65415 http://www.securitytracker.com/id/1029745 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-009
Share on: