ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_kernel | Linux | 2.4.0 (including) | 2.4.0 (including) |
Linux_kernel | Linux | 2.4.0-test1 (including) | 2.4.0-test1 (including) |
Linux_kernel | Linux | 2.4.1 (including) | 2.4.1 (including) |
Linux_kernel | Linux | 2.4.2 (including) | 2.4.2 (including) |
Linux_kernel | Linux | 2.4.3 (including) | 2.4.3 (including) |
Red Hat Linux 7.1 | RedHat | * |