PT-2001-2202 · Linux · Ip Masq Irc
Publicado
2001-07-30
·
Atualizado
2018-09-20
·
CVE-2001-1056
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ip masq irc version 2.2
Description
The issue allows remote attackers to bypass intended firewall restrictions. This is achieved by causing the target system to send a "DCC SEND" request to a malicious server listening on port 6667. As a result, the module may believe the traffic is a valid request and allow the connection to the port specified in the DCC SEND request.
Recommendations
For ip masq irc version 2.2, consider restricting access to the IRC DCC helper function in the ip masq irc IP masquerading module to minimize the risk of exploitation. As a temporary workaround, consider disabling the IRC DCC helper functionality until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ip Masq Irc