PT-2010-1198 · Sun · Sun One Web Server
Published
2010-02-05
·
Updated
2017-08-17
·
CVE-2003-1578
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Sun ONE (aka iPlanet) Web Server versions 4.1 through SP12
Sun ONE (aka iPlanet) Web Server versions 6.0 through SP5
Description
The issue allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format=" substring, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
Recommendations
For Sun ONE (aka iPlanet) Web Server versions 4.1 through SP12, consider disabling DNS resolution for client IP addresses to prevent exploitation.
For Sun ONE (aka iPlanet) Web Server versions 6.0 through SP5, consider disabling DNS resolution for client IP addresses to prevent exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun One Web Server