PT-2010-1198 · Sun · Sun One Web Server

Publicado

2010-02-05

·

Atualizado

2017-08-17

·

CVE-2003-1578

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Sun ONE (aka iPlanet) Web Server versions 4.1 through SP12 Sun ONE (aka iPlanet) Web Server versions 6.0 through SP5
Description The issue allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format=" substring, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
Recommendations For Sun ONE (aka iPlanet) Web Server versions 4.1 through SP12, consider disabling DNS resolution for client IP addresses to prevent exploitation. For Sun ONE (aka iPlanet) Web Server versions 6.0 through SP5, consider disabling DNS resolution for client IP addresses to prevent exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-1578

Produtos afetados

Sun One Web Server