PT-2002-2699 · Ipfilter · Ipfilter

Published

2002-12-31

·

Updated

2009-04-03

·

CVE-2002-1978

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IPFilter versions 3.1.1 through 3.4.28
Description The issue allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server. This generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server.
Recommendations For IPFilter versions 3.1.1 through 3.4.28, consider restricting access to the FTP server to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the PASV command in the FTP server configuration until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2002-1978

Affected Products

Ipfilter