Vulnerability Name: | CCN-35312 | ||||||
Published: | 2007-07-10 | ||||||
Updated: | 2007-07-10 | ||||||
Summary: | Sun Java could allow a remote attacker to spoof DNS responses, caused by a vulnerability in Java Virtual Machine DNS pinning. By persuading a victim to open a specially-crafted Web page, an attacker could exploit this vulnerability to bypass DNS pinning restrictions and possibly spoof hostnames and addresses in the DNS cache.
Note: In order to exploit this vulnerability, the attacker must provide a DNS response from the same subnet as the victim. | ||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
CVSS v2 Severity: | 2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N) 2.1 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
| ||||||
Vulnerability Consequences: | Bypass Security | ||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Mon Jul 09 2007 - 21:29:29 CDT Anti-DNS Pinning and Java Applets Source: CCN Type: Sun Java Web site Java Technology Source: XF Type: UNKNOWN java-subnet-dns-spoofing(35312) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |