CVE-2001-1388: Medium severity netfilter iptables vulnerability

Published Nov 5, 2001
·
Updated

iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator.

Affected Software

1 affected component
netfilter iptables<1.2.4

Event History

Nov 5, 2001
CVE Published
05:00 AM
Aug 31, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What configurations are exposed to this issue?

Systems using netfilter iptables before 1.2.4 are affected when administrators specify rate limits on the command line. The configured limit may be converted inaccurately, allowing more or less traffic than intended.

2

Does exploitation require authentication or local access?

No. The supplied vector indicates network access, low attack complexity, and no authentication requirement. An attacker or user who can generate traffic subject to an affected rate limit may be able to exceed or fall below the administrator's intended threshold.

3

How can I determine whether a system is affected?

Check whether the system runs an iptables version earlier than 1.2.4 and whether its rules use command-line-specified rate limits. Verify the effective traffic behavior against the configured limit, since the issue is inaccurate conversion of the specified rate.

4

What is the remediation?

Apply the available patch by updating iptables to a fixed version. After updating, review and test rate-limit rules to confirm that their effective limits match the administrator's intended settings.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203