PT-2002-2699 · Ipfilter · Ipfilter
Published
2002-12-31
·
Updated
2009-04-03
·
CVE-2002-1978
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IPFilter versions 3.1.1 through 3.4.28
Description
The issue allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server. This generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server.
Recommendations
For IPFilter versions 3.1.1 through 3.4.28, consider restricting access to the FTP server to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the PASV command in the FTP server configuration until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipfilter