Multiple Vendor HTTP Server IPv6 Socket IPv4 Mapped Address Handling Vulnerability
BID:8927
Info
Multiple Vendor HTTP Server IPv6 Socket IPv4 Mapped Address Handling Vulnerability
| Bugtraq ID: | 8927 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2003 12:00AM |
| Updated: | Oct 29 2003 12:00AM |
| Credit: | Vulnerability announced by itojun. |
| Vulnerable: |
IETF RFC 3513: Internet Protocol Version 6 Address Arch IETF RFC 3493: Basic Socket Interface Extensions IPv6 |
| Not Vulnerable: | |
Discussion
Multiple Vendor HTTP Server IPv6 Socket IPv4 Mapped Address Handling Vulnerability
A problem may exist in some web servers that may result in vulnerabilities in web applications. When a mapped IPv4 address is passed to a system through an IPv6 interface, it may be possible confuse or even take advantage of functions in web applications.
A problem may exist in some web servers that may result in vulnerabilities in web applications. When a mapped IPv4 address is passed to a system through an IPv6 interface, it may be possible confuse or even take advantage of functions in web applications.
Exploit / POC
Multiple Vendor HTTP Server IPv6 Socket IPv4 Mapped Address Handling Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor HTTP Server IPv6 Socket IPv4 Mapped Address Handling Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple Vendor HTTP Server IPv6 Socket IPv4 Mapped Address Handling Vulnerability
References:
References:
- IPv4-Mapped Address API Considered Harmful (IETF)
- RFC 3493: Basic Socket Interface Extensions for IPv6 (IETF)
- RFC 3513: Internet Protocol Version 6 (IPv6) Addressing Architecture (IETF)
- possible issue with IPv4 mapped address and $REMOTE_ADDR in CGI (
) - Re: possible issue with IPv4 mapped address and $REMOTE_ADDR in CGI (Colm MacCarthaigh
) - Re: possible issue with IPv4 mapped address and $REMOTE_ADDR in CGI (der Mouse
) - Re: possible issue with IPv4 mapped address and $REMOTE_ADDR in CGI (Colm MacCarthaigh
)