Product: Solaris 10 Operating System OpenSolaris

A security vulnerability in Solaris IP Filter (ipfilter(5)) when configured to provide Network Address Translation (NAT) service on DNS servers may allow remote unprivileged users to cause named(1M) to return incorrect addresses for Internet hosts, thereby redirecting end users to unintended hosts or services.

This vulnerability annuls the fix for the DNS Cache Poisoning Vulnerability described in Sun Alert 239392, available at:

Sun acknowledges with thanks, CERT/CC for bringing this issue to our
attention.

State: Resolved
First released: 11-Nov-2008
Permalink |

Comments:

Post a Comment:

Comments are closed for this entry.