CVE-2000-0339: High severity Zonelabs ZoneAlarm vulnerability
ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable filtering/blocking of UDP packets with source port 67 in ZoneAlarm to prevent firewall rule bypass.
ZoneAlarm filter_udp_source_port_67 = enabled - Compensating control
At the network perimeter or on upstream firewalls/routers, block or drop UDP packets with a source port of 67 or restrict such traffic to trusted hosts until a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0339?
CVE-2000-0339 is classified as a medium severity vulnerability.
How do I fix CVE-2000-0339?
To fix CVE-2000-0339, users should upgrade to ZoneAlarm version 2.1.11 or later, which includes a patch for this issue.
What systems are affected by CVE-2000-0339?
CVE-2000-0339 affects ZoneAlarm versions 2.1.10 and earlier.
What exploit does CVE-2000-0339 allow?
CVE-2000-0339 allows remote attackers to bypass firewall rules by sending UDP packets with a source port of 67.
Who is vulnerable to attacks exploiting CVE-2000-0339?
Users of ZoneAlarm versions 2.1.10 and earlier may be vulnerable to attacks exploiting CVE-2000-0339.