Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fhm-3w62-3q2q

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

EPSS

Процентиль: 70%
0.00655
Низкий

Связанные уязвимости

nvd
больше 15 лет назад

The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

debian
больше 15 лет назад

The Apache HTTP Server 2.0.44, when DNS resolution is enabled for clie ...

EPSS

Процентиль: 70%
0.00655
Низкий