PT-2001-2296 · Unknown · Tcp Wrappers
CVE-2001-1155
·
Publicado
2001-08-23
·
Atualizado
2024-02-16
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
tcp wrappers versions 4.1.1 through 4.3
Description
The issue concerns the improper checking of the result of a reverse DNS lookup in tcp wrappers when the PARANOID ACL option is enabled. This could allow remote attackers to bypass intended access restrictions via DNS spoofing.
Recommendations
For versions 4.1.1 through 4.3, consider disabling the PARANOID ACL option as a temporary workaround until a patch is available. Restrict access to the reverse DNS lookup functionality to minimize the risk of exploitation.
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tcp Wrappers