CVE-2001-1387: Infoleak
iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an information leak.
Affected Software
Event History
Frequently Asked Questions
What access or conditions are needed to exploit this issue?
The issue has a local attack vector and requires low attack complexity with no authentication. Exploitation depends on an administrator saving and later relying on a rule using "--reject-with icmp-host-prohibited."
How can I determine whether a saved ruleset is affected?
Inspect rulesets produced by iptables-save for reject rules originally configured with "--reject-with icmp-host-prohibited." An affected version records that rule as "--reject-with tcp-reset" instead.
What is the practical impact of the incorrect saved rule?
When the saved ruleset is used, iptables generates TCP reset responses instead of ICMP host-prohibited responses. This behavioral difference may disclose information.