IPTables FTP Stateful Inspection Arbitrary Filter Rule Insertion Vulnerability

BID:2602

Info

IPTables FTP Stateful Inspection Arbitrary Filter Rule Insertion Vulnerability

Bugtraq ID: 2602
Class: Failure to Handle Exceptional Conditions
CVE:
Remote: Yes
Local: No
Published: Apr 16 2001 12:00AM
Updated: Apr 16 2001 12:00AM
Credit: Discovered by Cristiano Lincoln Mattos <[email protected]> and published on April 16, 2001.
Vulnerable: Linux kernel 2.4.3
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0
Linux kernel 2.4.2
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 alpha
Linux kernel 2.4.1
Linux kernel 2.4 .0-test1
Linux kernel 2.4
Not Vulnerable:

Discussion

IPTables FTP Stateful Inspection Arbitrary Filter Rule Insertion Vulnerability

The Linux kernel includes a built-in firewall implementation called IPTables. IPTables supports stateful inspection of several application protocols, one of which is FTP. The inspection is used to facilitate outgoing PORT connections for FTP data transfers when clients or servers are behind firewalls.

When a FTP PORT command containing an IP address which differs from the client's is processed by the stateful-inspection module, the occurrance is caught. Despite being detected, the condition is handled erroneously causing an entry for the PORT connection to be inserted into the table of 'RELATED' connections. This temporarily permits traffic through the firewall from the FTP server to the destination included in the PORT command.

An attacker may be able to use this vulnerability to access unauthorized hosts from the FTP server.

It should be noted that clients do not need to authenticate to exploit this vulnerability.

Exploit / POC

IPTables FTP Stateful Inspection Arbitrary Filter Rule Insertion Vulnerability

Cristiano Lincoln Mattos <[email protected]> has provided proof-of-concept exploit code.

Solution / Fix

IPTables FTP Stateful Inspection Arbitrary Filter Rule Insertion Vulnerability

Solution:
Red Hat has released upgraded packages and an advisory. The kernel upgrade is split into several different RPMs, all of which should be applied. Some components are optimized for different versions of the Intel architecture, ie i586, i686. Administrators are advised to install the optimized packages where appropriate.

The NetFilter core development team has released a source-code patch that addresses this issue:


Linux kernel 2.4.2

Linux kernel 2.4.3

References

IPTables FTP Stateful Inspection Arbitrary Filter Rule Insertion Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report