5
CVSSv2

CVE-2003-1029

Published: 17/02/2004 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The L2TP protocol parser in tcpdump 3.8.1 and previous versions allows remote malicious users to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.

Vulnerable Product Search on Vulmon Subscribe to Product

lbl tcpdump 3.4

lbl tcpdump 3.6.3

lbl tcpdump 3.7

lbl tcpdump 3.5

lbl tcpdump 3.5.2

lbl tcpdump 3.6.2

Exploits

source: wwwsecurityfocuscom/bid/9263/info A vulnerability has been reported to exist in the software that may allow a remote attacker to cause a denial of service condition in tcpdump The issue presents itself when an attacker sends a maliciously formatted packet containing 0xff,0x02 bytes to UDP port 1701 of a system running a vulnerabl ...