IBM Information for VU#852283

Cached malformed SIG record buffer overflow



Vendor Statement

The AIX operating system is vulnerable to the named and DNS resolver issues in releases 4.3.3, 5.1.0 and 5.2.0. Temporary patches will be available through an efix package by 11/22/2002 or before. The efix will be available at the following URL:

In the interim, customers may want to implement the workarounds given in the Solutions section to limit their exposure.

The following APARs will be available in the near future:
    AIX 4.3.3 APAR IY37088 (available approx 11/27/2002 )
    AIX 5.1.0 APAR IY37019 (available approx 12/18/2002 )
    AIX 5.2.0 APAR TBA (available approx TBA )

    Vendor Information

    The vendor has not provided us with any further information regarding this vulnerability.

    Vendor References



    The CERT/CC has no additional comments at this time.

    If you have feedback, comments, or additional information about this vulnerability, please send us email.