|
|
Info |
Last Modified |
| 7 months ago |
|
|
|
|
Description |
tcpdump contains a flaw that may allow a remote denial of service. The issue is triggered when a crafted BGP packet is parsed, causing an infinite loop, and will result in loss of availability for the service.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Availability
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Technical |
The bgp_update_print function in tcpdump 3.8.3 and some versions of the 3.9 release train (3.9.2 and prior plus some CVS versions) enters an infinite loop when passed a -1 return value from the decode_prefix4 function. Tcpdump captures that include a BGP4 packet so crafted will cause a denial of service of the tcpdump program.
|
|
Solution |
Upgrade to version 3.9.3 or higher from CVS, as it has been reported to fix this vulnerability. In addition, Simon Nielsen has released a patch for some older versions.
|
|
Products |
|
tcpdump
 |
3.8.3 |
3.9 |
|
|
|
|
|
|
Credit |
- Frédéric Raynal - pappy
security-labs.org - Security Labs
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|