vendor:
tcpdump
by:
Remi Denis-Courmont
2,6
CVSS
LOW
Denial of Service
190
CWE
Product Name: tcpdump
Affected Version From: 3.8.1
Affected Version To: 3.8.2
Patch Exists: YES
Related CWE: CAN-2004-0184
CPE: tcpdump
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Mac, Windows
2004
Integer underflow in ISAKMP Identification payload denial of service vulnerability
Integer underflow in ISAKMP Identification payload denial of service vulnerability is a vulnerability in tcpdump packet sniffer which can be exploited to cause a denial of service. The vulnerability was found by Rapid7, LLC Security Advisory and affects tcpdump 3.8.1. The vulnerability cannot be exploited to cause a denial of service with the Debian's tcpdump packages as it was partly fixed as part of the fix for earlier known CAN-2003-0108 vulnerability, though the bug is still present. That may be the case for other vendors which were not investigated. tcpdump must be run with a verbosity level of at least 3: # tcpdump -vvv Otherwise, no denial of service will occur.
Mitigation:
Upgrade to tcpdump 3.8.3 or later version.