CVE-2001-1388: Medium severity netfilter iptables vulnerability
iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What configurations are exposed to this issue?
Systems using netfilter iptables before 1.2.4 are affected when administrators specify rate limits on the command line. The configured limit may be converted inaccurately, allowing more or less traffic than intended.
Does exploitation require authentication or local access?
No. The supplied vector indicates network access, low attack complexity, and no authentication requirement. An attacker or user who can generate traffic subject to an affected rate limit may be able to exceed or fall below the administrator's intended threshold.
How can I determine whether a system is affected?
Check whether the system runs an iptables version earlier than 1.2.4 and whether its rules use command-line-specified rate limits. Verify the effective traffic behavior against the configured limit, since the issue is inaccurate conversion of the specified rate.
What is the remediation?
Apply the available patch by updating iptables to a fixed version. After updating, review and test rate-limit rules to confirm that their effective limits match the administrator's intended settings.