First published: Fri May 26 2000(Updated: )
Race condition in IPFilter firewall 3.4.3 and earlier, when configured with overlapping "return-rst" and "keep state" rules, allows remote attackers to bypass access restrictions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phildev IPFilter | =3.3.15 | |
Phildev IPFilter | =3.4.3 | |
=3.3.15 | ||
=3.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0553 is considered to have a high severity due to the potential for remote attackers to bypass access restrictions.
To fix CVE-2000-0553, you should upgrade to a version of IPFilter that does not contain this vulnerability, specifically versions later than 3.4.3.
CVE-2000-0553 is caused by a race condition in IPFilter when using conflicting "return-rst" and "keep state" rules.
CVE-2000-0553 affects users of IPFilter versions 3.4.3 and earlier deployed in configurations with overlapping rules.
Yes, CVE-2000-0553 can be exploited remotely, allowing attackers to bypass firewall access restrictions.