PT-2014-6187 · Contiki+1 · Uip+1

Allen D. Householder

·

Publicado

2014-11-28

·

Atualizado

2015-01-08

·

CVE-2014-4883

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions lwIP versions 1.4.1 and earlier uIP (affected versions not specified)
Description The issue concerns the DNS resolver in uIP and lwIP, where the resolv.c and dns.c files do not utilize random values for ID fields and source ports of DNS query packets. This oversight facilitates man-in-the-middle attacks, as attackers can conduct cache-poisoning attacks via spoofed reply packets.
Recommendations For lwIP versions 1.4.1 and earlier, consider updating to a version that incorporates randomization for ID fields and source ports in DNS queries. For uIP, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-4883

Produtos afetados

Lwip
Uip