CVE-2001-0969: Critical severity FreeBSD FreeBSD vulnerability
Published Aug 31, 2001
·Updated
ipfw in FreeBSD does not properly handle the use of "me" in its rules when point to point interfaces are used, which causes ipfw to allow connections from arbitrary remote hosts.
Affected Software
1 affected component
FreeBSD FreeBSD=4.3
Remediation
Patch Available
Event History
Aug 31, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0969?
CVE-2001-0969 has a moderate severity rating due to its potential to allow unauthorized access to systems.
2
What software is affected by CVE-2001-0969?
CVE-2001-0969 specifically affects FreeBSD version 4.3.
3
How do I fix CVE-2001-0969?
To fix CVE-2001-0969, update FreeBSD to a version that addresses this vulnerability.
4
What is the nature of the vulnerability in CVE-2001-0969?
CVE-2001-0969 occurs when ipfw fails to properly handle rules using "me" on point-to-point interfaces, allowing unintended connections.
5
Can CVE-2001-0969 be exploited remotely?
Yes, CVE-2001-0969 can be exploited by remote attackers due to the improper handling of ipfw rules.