Lucene search

K
ubuntuUbuntuUSN-141-1
HistoryJun 21, 2005 - 12:00 a.m.

tcpdump vulnerability

2005-06-2100:00:00
ubuntu.com
32

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.068

Percentile

93.9%

Releases

  • Ubuntu 5.04
  • Ubuntu 4.10

Details

It was discovered that certain invalid BGP packets triggered an
infinite loop in tcpdump, which caused tcpdump to stop working. This
could be abused by a remote attacker to bypass tcpdump analysis of
network traffic.

OSVersionArchitecturePackageVersionFilename
Ubuntu5.04noarchtcpdump< *UNKNOWN
Ubuntu4.10noarchtcpdump< *UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.068

Percentile

93.9%