5
CVSSv2

CVE-2003-0108

Published: 07/03/2003 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

isakmp_sub_print in tcpdump 3.6 up to and including 3.7.1 allows remote malicious users to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.

Vulnerable Product Search on Vulmon Subscribe to Product

lbl tcpdump 3.7

lbl tcpdump 3.7.1

lbl tcpdump 3.5.2

lbl tcpdump 3.6.2

Vendor Advisories

Andrew Griffiths and iDEFENSE Labs discovered a problem in tcpdump, a powerful tool for network monitoring and data acquisition An attacker is able to send a specially crafted network packet which causes tcpdump to enter an infinite loop In addition to the above problem the tcpdump developers discovered a potential infinite loop when parsing malf ...

Exploits

source: wwwsecurityfocuscom/bid/6974/info It has been reported that tcpdump is vulnerable to a denial of service when some packet types are received By sending a maliciously formatted packet to a system using a vulnerable version of tcpdump, it is possible for a remote user to cause tcpdump to ignore network traffic from the time the pac ...