Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by triggering a communications loop via (a) DNS query packets with localhost as a spoofed source address, or (b) a response packet that triggers a response packet.
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
AV:N/AC:L/Au:N/C:N/I:N/A:P
Vendors | Products |
---|---|
Maradns |
|
Pliant |
|
Qbik |
|
Axis |
|
Dnrd |
|
Don Moore |
|
Team Johnlong |
|
Delegate |
|
Posadis |
|
Configuration 1 [-]
|
Configuration 2 [-]
|
References
Link | Resource |
---|---|
http://secunia.com/advisories/13145 | Patch |
http://securitytracker.com/id?1012157 | Patch |
http://www.niscc.gov.uk/niscc/docs/al-20041130-00862.html?lang=en | Vendor Advisory |
http://www.niscc.gov.uk/niscc/docs/re-20041109-00957.pdf | Vendor Advisory |
http://www.posadis.org/advisories/pos_adv_006.txt | Patch Vendor Advisory |
http://www.securityfocus.com/bid/11642 | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17997 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2005-09-01T04:00:00
Updated: 2017-07-10T14:57:01
Reserved: 2004-08-17T00:00:00
Link: CVE-2004-0789
JSON object: View
NVD Information
Status : Modified
Published: 2004-12-31T05:00:00.000
Modified: 2017-07-11T01:30:28.667
Link: CVE-2004-0789
JSON object: View
Redhat Information
No data.
CWE