CVE-2006-4562

Symantec Gateway Security - Unauthenticated DNS Query Proxy Abuse

Title source: llm
STIX 2.1

Description

The proxy DNS service in Symantec Gateway Security (SGS) allows remote attackers to make arbitrary DNS queries to third-party DNS servers, while hiding the source IP address of the attacker. NOTE: another researcher has stated that the default configuration does not proxy DNS queries received on the external interface

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/444114/100/100/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/444134/100/100/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/444330/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/444135/100/100/threaded

Scores

EPSS 0.0116
EPSS Percentile 78.8%

Details

Status published
Products (15)
symantec/gateway_security 1.0
symantec/gateway_security 320
symantec/gateway_security 360
symantec/gateway_security 360r
symantec/gateway_security 5000_series_2.0.1
symantec/gateway_security 5000_series_3.0
symantec/gateway_security 5110
symantec/gateway_security 5110_1.0
symantec/gateway_security 5200
symantec/gateway_security 5200_1.0
... and 5 more
Published Sep 06, 2006
Tracked Since Feb 18, 2026