Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51199
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2003:033
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2003:033.

Updated tcpdump, libpcap, and arpwatch packages are available to fix an
incorrect bounds check when decoding BGP packets and a possible denial of
service.

Tcpdump is a command-line tool for monitoring network traffic.

The BGP decoding routines in tcpdump before version 3.6.2 used incorrect
bounds checking when copying data, which allows remote attackers to cause a
denial of service and possibly execute arbitrary code (as the 'pcap' user).

If a UDP packet from a radius port contains 0 at the second byte tcpdump
gets stuck in a loop that generating an infinite stream of '#0#0#0#0#0'.
This could be used as a denial of service.

Users of tcpdump are advised to upgrade to these errata packages which
contain patches to correct thes issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2003-033.html

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-1350
BugTraq ID: 6213
http://www.securityfocus.com/bid/6213
Bugtraq: 20021219 TSLSA-2002-0084 - tcpdump (Google Search)
http://marc.info/?l=bugtraq&m=104032975103398&w=2
Caldera Security Advisory: CSSA-2002-050.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-050.0.txt
Debian Security Information: DSA-206 (Google Search)
http://www.debian.org/security/2002/dsa-206
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027
http://www.tcpdump.org/lists/workers/2001/10/msg00101.html
http://www.redhat.com/support/errata/RHSA-2003-032.html
http://www.redhat.com/support/errata/RHSA-2003-033.html
http://www.redhat.com/support/errata/RHSA-2003-214.html
XForce ISS Database: tcpdump-sizeof-memory-corruption(10695)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10695
Common Vulnerability Exposure (CVE) ID: CVE-2003-0093
Debian Security Information: DSA-261 (Google Search)
http://www.debian.org/security/2003/dsa-261
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585
XForce ISS Database: tcpdump-radius-decoder-dos(11324)
https://exchange.xforce.ibmcloud.com/vulnerabilities/11324
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.