CVE Vulnerabilities

CVE-2002-1978

Published: Dec 31, 2002 | Modified: Apr 03, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server.

Affected Software

Name Vendor Start Version End Version
Ipfilter Darren_reed 3.1.1 (including) 3.1.1 (including)
Ipfilter Darren_reed 3.1.2 (including) 3.1.2 (including)
Ipfilter Darren_reed 3.1.3 (including) 3.1.3 (including)
Ipfilter Darren_reed 3.1.4 (including) 3.1.4 (including)
Ipfilter Darren_reed 3.1.5 (including) 3.1.5 (including)
Ipfilter Darren_reed 3.1.6 (including) 3.1.6 (including)
Ipfilter Darren_reed 3.1.7 (including) 3.1.7 (including)
Ipfilter Darren_reed 3.1.8 (including) 3.1.8 (including)
Ipfilter Darren_reed 3.1.9 (including) 3.1.9 (including)
Ipfilter Darren_reed 3.1.10 (including) 3.1.10 (including)
Ipfilter Darren_reed 3.2.1 (including) 3.2.1 (including)
Ipfilter Darren_reed 3.2.2 (including) 3.2.2 (including)
Ipfilter Darren_reed 3.2.3 (including) 3.2.3 (including)
Ipfilter Darren_reed 3.2.4 (including) 3.2.4 (including)
Ipfilter Darren_reed 3.2.5 (including) 3.2.5 (including)
Ipfilter Darren_reed 3.2.6 (including) 3.2.6 (including)
Ipfilter Darren_reed 3.2.7 (including) 3.2.7 (including)
Ipfilter Darren_reed 3.2.8 (including) 3.2.8 (including)
Ipfilter Darren_reed 3.2.9 (including) 3.2.9 (including)
Ipfilter Darren_reed 3.2.10 (including) 3.2.10 (including)
Ipfilter Darren_reed 3.2.11 (including) 3.2.11 (including)
Ipfilter Darren_reed 3.2.12 (including) 3.2.12 (including)
Ipfilter Darren_reed 3.2.13 (including) 3.2.13 (including)
Ipfilter Darren_reed 3.2.14 (including) 3.2.14 (including)
Ipfilter Darren_reed 3.2.15 (including) 3.2.15 (including)
Ipfilter Darren_reed 3.2.16 (including) 3.2.16 (including)
Ipfilter Darren_reed 3.2.17 (including) 3.2.17 (including)
Ipfilter Darren_reed 3.2.18 (including) 3.2.18 (including)
Ipfilter Darren_reed 3.2.19 (including) 3.2.19 (including)
Ipfilter Darren_reed 3.2.20 (including) 3.2.20 (including)
Ipfilter Darren_reed 3.2.21 (including) 3.2.21 (including)
Ipfilter Darren_reed 3.2.22 (including) 3.2.22 (including)
Ipfilter Darren_reed 3.3.1 (including) 3.3.1 (including)
Ipfilter Darren_reed 3.3.2 (including) 3.3.2 (including)
Ipfilter Darren_reed 3.3.3 (including) 3.3.3 (including)
Ipfilter Darren_reed 3.3.4 (including) 3.3.4 (including)
Ipfilter Darren_reed 3.3.5 (including) 3.3.5 (including)
Ipfilter Darren_reed 3.3.6 (including) 3.3.6 (including)
Ipfilter Darren_reed 3.3.7 (including) 3.3.7 (including)
Ipfilter Darren_reed 3.3.8 (including) 3.3.8 (including)
Ipfilter Darren_reed 3.3.9 (including) 3.3.9 (including)
Ipfilter Darren_reed 3.3.10 (including) 3.3.10 (including)
Ipfilter Darren_reed 3.3.11 (including) 3.3.11 (including)
Ipfilter Darren_reed 3.3.12 (including) 3.3.12 (including)
Ipfilter Darren_reed 3.3.13 (including) 3.3.13 (including)
Ipfilter Darren_reed 3.3.14 (including) 3.3.14 (including)
Ipfilter Darren_reed 3.3.15 (including) 3.3.15 (including)
Ipfilter Darren_reed 3.3.16 (including) 3.3.16 (including)
Ipfilter Darren_reed 3.3.17 (including) 3.3.17 (including)
Ipfilter Darren_reed 3.3.18 (including) 3.3.18 (including)
Ipfilter Darren_reed 3.3.19 (including) 3.3.19 (including)
Ipfilter Darren_reed 3.3.20 (including) 3.3.20 (including)
Ipfilter Darren_reed 3.3.21 (including) 3.3.21 (including)
Ipfilter Darren_reed 3.3.22 (including) 3.3.22 (including)
Ipfilter Darren_reed 3.4.1 (including) 3.4.1 (including)
Ipfilter Darren_reed 3.4.2 (including) 3.4.2 (including)
Ipfilter Darren_reed 3.4.3 (including) 3.4.3 (including)
Ipfilter Darren_reed 3.4.4 (including) 3.4.4 (including)
Ipfilter Darren_reed 3.4.5 (including) 3.4.5 (including)
Ipfilter Darren_reed 3.4.6 (including) 3.4.6 (including)
Ipfilter Darren_reed 3.4.7 (including) 3.4.7 (including)
Ipfilter Darren_reed 3.4.8 (including) 3.4.8 (including)
Ipfilter Darren_reed 3.4.9 (including) 3.4.9 (including)
Ipfilter Darren_reed 3.4.10 (including) 3.4.10 (including)
Ipfilter Darren_reed 3.4.11 (including) 3.4.11 (including)
Ipfilter Darren_reed 3.4.12 (including) 3.4.12 (including)
Ipfilter Darren_reed 3.4.13 (including) 3.4.13 (including)
Ipfilter Darren_reed 3.4.14 (including) 3.4.14 (including)
Ipfilter Darren_reed 3.4.15 (including) 3.4.15 (including)
Ipfilter Darren_reed 3.4.16 (including) 3.4.16 (including)
Ipfilter Darren_reed 3.4.17 (including) 3.4.17 (including)
Ipfilter Darren_reed 3.4.18 (including) 3.4.18 (including)
Ipfilter Darren_reed 3.4.19 (including) 3.4.19 (including)
Ipfilter Darren_reed 3.4.20 (including) 3.4.20 (including)
Ipfilter Darren_reed 3.4.21 (including) 3.4.21 (including)
Ipfilter Darren_reed 3.4.22 (including) 3.4.22 (including)
Ipfilter Darren_reed 3.4.23 (including) 3.4.23 (including)
Ipfilter Darren_reed 3.4.24 (including) 3.4.24 (including)
Ipfilter Darren_reed 3.4.25 (including) 3.4.25 (including)
Ipfilter Darren_reed 3.4.26 (including) 3.4.26 (including)
Ipfilter Darren_reed 3.4.27 (including) 3.4.27 (including)
Ipfilter Darren_reed 3.4.28 (including) 3.4.28 (including)

References