CVE-2002-1978: High severity Darren Reed IPFilter vulnerability
IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1978?
CVE-2002-1978 is considered a high-severity vulnerability as it allows remote attackers to bypass firewall rules.
How do I fix CVE-2002-1978?
To fix CVE-2002-1978, upgrade to a patched version of IPFilter that has addressed this vulnerability.
Which versions of IPFilter are affected by CVE-2002-1978?
CVE-2002-1978 affects IPFilter versions 3.1.1 through 3.4.28.
What type of vulnerability is CVE-2002-1978?
CVE-2002-1978 is a firewall rule bypass vulnerability specifically targeting FTP server interactions.
Can CVE-2002-1978 be exploited remotely?
Yes, CVE-2002-1978 can be exploited by remote attackers without needing physical access to the system.