7.5
CVSSv2

CVE-2003-0850

Published: 17/11/2003 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The TCP reassembly functionality in libnids prior to 1.18 allows remote malicious users to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rafal wojtczuk libnids 1.17

dug song dsniff 2.3

rafal wojtczuk libnids 1.14

rafal wojtczuk libnids 1.16

rafal wojtczuk libnids 1.11

rafal wojtczuk libnids 1.12

rafal wojtczuk libnids 1.13

Vendor Advisories

A vulnerability was discovered in libnids, a library used to analyze IP network traffic, whereby a carefully crafted TCP datagram could cause memory corruption and potentially execute arbitrary code with the privileges of the user executing a program which uses libnids (such as dsniff) For the current stable distribution (woody) this problem has b ...