| Vulnerabilities in Apple Bonjour |
|
|
| Written by Rebecca Mints |
| Thursday, 11 September 2008 01:51 |
|
Two vulnerabilities have been identified in Apple Bonjour for Windows, which could be exploited by attackers to cause a denial of service or spoof DNS responses.
The first issue is caused by a NULL pointer dereference error in the Bonjour Namespace Provider when resolving a specially crafted ".local" domain name containing a long DNS label, which could be exploited to crash an affected application.
The second vulnerability is caused by an error in the DNS protocol, which may allow a remote attacker to spoof DNS responses.
Source: http://www.frsirt.com/english/advisories/2008/2524 |