First published: Fri Feb 05 2010(Updated: )
Sun ONE (aka iPlanet) Web Server 6 on Windows, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iPlanet Web Server | =6.0 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1579 is considered a medium severity vulnerability due to its exploitation potential in server logging.
To fix CVE-2003-1579, disable DNS resolution for client IP addresses in the Sun ONE Web Server settings.
CVE-2003-1579 affects Sun ONE Web Server version 6.0 running on Microsoft Windows.
Yes, CVE-2003-1579 can be exploited remotely by sending crafted DNS responses to the server.
The main risk of CVE-2003-1579 is an attacker being able to spoof IP addresses in server logs, potentially leading to further attacks.