Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Traffic Server输入验证漏洞
Vulnerability Description
Apache Traffic Server是高效、可扩展的缓存代理服务器。 Apache Traffic Server 2.0.1之前的版本,2.1.2-unstable之前的2.1.x版本不能正确选择DNS源端口和处理ID,也不能正确使用DNS查询域来验证响应。中间人攻击者可以借助特制的响应使内部DNS缓存中毒。
CVSS Information
N/A
Vulnerability Type
N/A