Description: | Description:
The remote host is missing an update to tcpdump announced via advisory FEDORA-2007-654.
Tcpdump is a command-line tool for monitoring network traffic. Tcpdump can capture and display the packet headers on a particular network interface or on all interfaces. Tcpdump can display all of the packet headers, or just the ones that match particular criteria.
Install tcpdump if you need a program to monitor network traffic.
Update Information:
CVE-2007-3798 Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value. * Wed Aug 1 2007 Miroslav Lichvar - 14:3.9.4-11.fc6 - fix buffer overflow in BGP dissector (#250290, CVE-2007-3798) - with -C option, drop root privileges before opening first savefile (#244860)
Solution: Apply the appropriate updates.
This update can be downloaded from: http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at http://fedora.redhat.com/docs/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2007-654
Risk factor : High
CVSS Score: 6.8
|