|
|
|
Vulnerability Note VU#174086tcpdump contains vulnerability in ISAKMP decoding function rawprint() in print-isakmp.cOverviewtcpdump contains a vulnerability in the way it parses Internet Security Association and Key Management Protocol (ISAKMP) packets.I. Descriptiontcpdump is a widely-used network sniffer that is capable of decoding ISAKMP packets. A vulnerability exists in the way the tcpdump rawprint() function (in print-isakmp.c) parses certain malformed ISAKMP packets containing an invalid "len" or "loc" value. For more information, please see RHSA-2004-007.II. ImpactA remote attacker could cause a denial of service or possibly execute arbitrary code with privileges of the tcpdump process.III. SolutionUpgrade or Apply PatchUpgrade or apply a patch as specified by your vendor.
References
This vulnerability was originally reported by Red Hat, Inc. Red Hat, in turn, credits Jonathan Heusser for discovering this vulnerability. This document was written by Damon Morda.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||