| Description: | The remote host is missing updates announced in advisory CLSA-2005:986.
1.CVE-2005-1278[2] The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.
2.CVE-2005-1279[3] tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a specially crafted BGP packet, which is not properly handled by RT_ROUTING_INFO, or LDP packet, which is not properly handled by the ldp_print function.
3.CVE-2005-1280[4] The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.
Solution: The apt tool can be used to perform RPM package upgrades by running 'apt-get update' followed by 'apt-get upgrade'
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000986 http://www.tcpdump.org/
Risk factor : Medium |