CVE-2001-0405
ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.3%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 10.25% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-04/0271.htmlExploit, Patch, Vendor Advisory
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-071.php3
- http://www.redhat.com/support/errata/RHSA-2001-052.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2001-084.html
- http://www.securityfocus.com/bid/2602Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6390
- http://archives.neohapsis.com/archives/bugtraq/2001-04/0271.htmlExploit, Patch, Vendor Advisory
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-071.php3
- http://www.redhat.com/support/errata/RHSA-2001-052.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2001-084.html
- http://www.securityfocus.com/bid/2602Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6390
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.