CVE-2003-1580

Source
https://nvd.nist.gov/vuln/detail/CVE-2003-1580
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2003-1580.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2003-1580
Downstream
Published
2010-02-05T22:30:02Z
Modified
2025-08-09T19:01:27Z
Summary
[none]
Details

The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

References

Affected packages