Improper access control in Linux kernel - CVE-2001-0405

 

Improper access control in Linux kernel - CVE-2001-0405

Published: July 2, 2001 / Updated: November 7, 2024


Vulnerability identifier: #VU100008
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2001-0405
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.


Affected software

Linux kernel

How to mitigate CVE-2001-0405

Install update from vendor's repository.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins