5
CVSSv2

CVE-2005-1279

Published: 02/05/2005 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

tcpdump 3.8.3 and previous versions allows remote malicious users to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.

Vulnerable Product Search on Vulmon Subscribe to Product

lbl tcpdump

Vendor Advisories

It was discovered that certain invalid GRE, LDP, BGP, and RSVP packets triggered infinite loops in tcpdump, which caused tcpdump to stop working This could be abused by a remote attacker to bypass tcpdump analysis of network traffic ...
Synopsis tcpdump security update Type/Severity Security Advisory: Moderate Topic Updated tcpdump packages that fix several security issues are now availableThis update has been rated as having moderate security impact by the RedHat Security Response TeamThis updated package also adds support for output fi ...
Synopsis tcpdump security update Type/Severity Security Advisory: Moderate Topic Updated tcpdump packages that fix several security issues are now availableThis update has been rated as having moderate security impact by the RedHat Security Response TeamThese updated packages also add support for output f ...

Exploits

/*[ tcpdump[38x]: (LDP) ldp_print() infinite loop DOS ]********* * * * by: vade79/v9 v9@fakehalous (fakehalo/realhalo) * * * * compile: * * gcc x ...
/*[ tcpdump[38x]: (BGP) RT_ROUTING_INFO infinite loop DOS ]***** * * * by: vade79/v9 v9@fakehalous (fakehalo/realhalo) * * * * compile: * * gcc x ...