CVE-2001-0908

CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).
Configurations

Configuration 1 (hide)

cpe:2.3:a:citrix:metaframe:1.8:*:*:*:*:*:*:*

History

20 Nov 2024, 23:36

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=100638693315933&w=2 - () http://marc.info/?l=bugtraq&m=100638693315933&w=2 -
References () http://www.securityfocus.com/bid/3566 - Vendor Advisory () http://www.securityfocus.com/bid/3566 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/7538 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/7538 -

Information

Published : 2001-11-21 05:00

Updated : 2024-11-20 23:36


NVD link : CVE-2001-0908

Mitre link : CVE-2001-0908

CVE.ORG link : CVE-2001-0908


JSON object : View

Products Affected

citrix

  • metaframe