5
CVSSv2

CVE-2005-1280

Published: 02/05/2005 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The rsvp_print function in tcpdump 3.9.1 and previous versions allows remote malicious users to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.

Vulnerable Product Search on Vulmon Subscribe to Product

lbl tcpdump

Vendor Advisories

It was discovered that certain invalid GRE, LDP, BGP, and RSVP packets triggered infinite loops in tcpdump, which caused tcpdump to stop working This could be abused by a remote attacker to bypass tcpdump analysis of network traffic ...
Synopsis tcpdump security update Type/Severity Security Advisory: Moderate Topic Updated tcpdump packages that fix several security issues are now availableThis update has been rated as having moderate security impact by the RedHat Security Response TeamThis updated package also adds support for output fi ...
Synopsis tcpdump security update Type/Severity Security Advisory: Moderate Topic Updated tcpdump packages that fix several security issues are now availableThis update has been rated as having moderate security impact by the RedHat Security Response TeamThese updated packages also add support for output f ...

Exploits

/*[ tcpdump(/ethereal)[]: (RSVP) rsvp_print() infinite loop DOS ]* * * * by: vade79/v9 v9@fakehalous (fakehalo/realhalo) * * * * compile: * * gcc x ...