DNS: Symantec Gateway Products DNS Cache Poisoning

This signature detects attempts to exploit a known vulnerability in the way the DNS proxy component of Symantec Gateway products processes and caches DNS responses. A successful attack can lead to man-in-the-middle attacks, or spoofing attacks, or information gathering attacks, etc.

Extended Description

A remote DNS cache poisoning vulnerability affects Symantec Gateway Security. The underlying issue causing this vulnerability is currently unknown. An attacker may leverage this issue to manipulate cache data, potentially facilitating man-in-the-middle, site impersonation, or denial of service attacks.

Affected Products

Symantec gateway_security_5400,Symantec enterprise_firewall

References

BugTraq: 12818

CVE: CVE-2005-0817

Short Name
DNS:QUERY:SYMC-DNS-CACHE
Severity
Minor
Recommended
False
Recommended Action
None
Category
DNS
Keywords
CVE-2005-0817 Cache DNS Gateway Poisoning Products Symantec bid:12818
Release Date
05/23/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Symantec

CVSS Score

5.0

Found a potential security threat?