PT-2001-2202 · Linux · Ip Masq Irc

Published

2001-07-30

·

Updated

2018-09-20

·

CVE-2001-1056

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ip masq irc version 2.2
Description The issue allows remote attackers to bypass intended firewall restrictions. This is achieved by causing the target system to send a "DCC SEND" request to a malicious server listening on port 6667. As a result, the module may believe the traffic is a valid request and allow the connection to the port specified in the DCC SEND request.
Recommendations For ip masq irc version 2.2, consider restricting access to the IRC DCC helper function in the ip masq irc IP masquerading module to minimize the risk of exploitation. As a temporary workaround, consider disabling the IRC DCC helper functionality until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1056

Affected Products

Ip Masq Irc