Lucene search

K
kasperskyKaspersky LabKLA10074
HistorySep 10, 2008 - 12:00 a.m.

KLA10074 Multiple vulnerabilities in Apple Bonjour

2008-09-1000:00:00
Kaspersky Lab
threats.kaspersky.com
23

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.7

Confidence

Low

EPSS

0.011

Percentile

84.4%

Multiple serious vulnerabilities have been found in Apple Bonjour. Malicious users can exploit these vulnerabilities to spoof DNS responses or cause denial of service Below is a complete list of vulnerabilities

  1. Not exploiting random transaction ID’s can be exploited remotely by spoofing DNS responses;
  2. Vectors related to mDNSResponder can be exploited via a specially designed .local domain.

Original advisories

Related products

Apple-Bonjour-for-Windows

CVE list

CVE-2008-2326 critical

Solution

Update to latest version

Impacts

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Apple Bonjour versions 1.0.4 and earlier for Windows

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.7

Confidence

Low

EPSS

0.011

Percentile

84.4%