PT-2010-1198 · Sun · Sun One Web Server

Published

2010-02-05

·

Updated

2017-08-17

·

CVE-2003-1578

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Sun ONE (aka iPlanet) Web Server versions 4.1 through SP12 Sun ONE (aka iPlanet) Web Server versions 6.0 through SP5
Description The issue allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format=" substring, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
Recommendations For Sun ONE (aka iPlanet) Web Server versions 4.1 through SP12, consider disabling DNS resolution for client IP addresses to prevent exploitation. For Sun ONE (aka iPlanet) Web Server versions 6.0 through SP5, consider disabling DNS resolution for client IP addresses to prevent exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1578

Affected Products

Sun One Web Server