CVE-2001-1387
published 2001-11-05CVE-2001-1387: iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.40%
32.4th percentile
iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an information leak.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netfilter | iptables | < 1.2.4 | 1.2.4 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2wcp-prmg-9pr7: iptables-save in iptables before 1
ghsa_unreviewed·2022-04-30
CVE-2001-1387 [LOW] CWE-200 GHSA-2wcp-prmg-9pr7: iptables-save in iptables before 1
iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an information leak.
Red Hat
security flaw
vendor_redhat·2001-10-30·CVSS 2.1
CVE-2001-1387 [LOW] security flaw
security flaw
iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an information leak.
No detection rules found.
No public exploits indexed.
CWE
Observable Discrepancy
mitre_cwe
CWE-203 Observable Discrepancy
CWE-203: Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Discrepancies can take many forms, and variations may be detectable in timing, control flow, communications such as replies or requests, or general behavior. These discrepancies can reveal information about the product's operation or internal state to an unauthorized actor. In some cases, discrepancies can be used by attackers to form a side channel.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Common Consequences:
Scope: Confidentiality, Access
CWE
The UI Performs the Wrong Action
mitre_cwe·CVSS 5.0
CVE-2001-1387 [MEDIUM] CWE-449 The UI Performs the Wrong Action
CWE-449: The UI Performs the Wrong Action
The UI performs the wrong action with respect to the user's request.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Other. Impact: Quality Degradation, Varies by Context.
Detection Methods:
Manual Analysis: Perform extensive functionality testing of the UI. The UI should behave as specified.
Observed Examples:
CVE-2001-1387: Network firewall accidentally implements one command line option as if it were another, possibly leading to behavioral infoleak.
CVE-2001-0081: Command line option correctly suppresses a user prompt but does not properly disable a feature, although when the product prompts the user, the feature is properly disabled.
CVE-2002-1977: Product does not "time out" according to user specification, leavin
CWE
Observable Response Discrepancy
mitre_cwe
CWE-204 Observable Response Discrepancy
CWE-204: Observable Response Discrepancy
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
Modes of Introduction:
Phase: Architecture and Design
Note: An observable response discrepancy frequently occurs during authentication, where a difference in failed-login messages could allow an attacker to determine if the username is valid or not. The discrepancy could be inadvertent (bug) or intentional (design).
Phase: Implementation
Note: An observable response discrepancy frequently occurs during authentication, where a difference in failed-login messages could allow an attacker to determine if the username is valid or not. The discrepancy could be inadvertent (bug) or
2001-11-05
Published