CVE-2003-1579: Medium severity Sun ONE Web Server vulnerability
Sun ONE (aka iPlanet) Web Server 6 on Windows, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1579?
CVE-2003-1579 is considered a medium severity vulnerability due to its exploitation potential in server logging.
How do I fix CVE-2003-1579?
To fix CVE-2003-1579, disable DNS resolution for client IP addresses in the Sun ONE Web Server settings.
What systems are affected by CVE-2003-1579?
CVE-2003-1579 affects Sun ONE Web Server version 6.0 running on Microsoft Windows.
Can CVE-2003-1579 be exploited remotely?
Yes, CVE-2003-1579 can be exploited remotely by sending crafted DNS responses to the server.
What is the main risk associated with CVE-2003-1579?
The main risk of CVE-2003-1579 is an attacker being able to spoof IP addresses in server logs, potentially leading to further attacks.