The default configuration of Name Service Cache Daemon (nscd) in Caldera OpenLinux 3.1 and 3.1.1 uses cached PTR records instead of consulting the authoritative DNS server for the A record, which could make it easier for remote attackers to bypass applications that restrict access based on host names.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/8745.php | vdb entry vendor advisory |
http://www.securityfocus.com/bid/4399 | vdb entry patch vendor advisory |
http://www.calderasystems.com/support/security/advisories/CSSA-2002-013.0.txt | vendor advisory |