Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian: DSA-255-1 Critical Advisory for Tcpdump Infinite Loop DoS

debian
Calendar Grey February 28, 2003
Debian Logo
Protect your system's integrity by adhering to Debian's advice on a Denial of Service vulnerability in tcpdump. Update to the latest release to prevent service disruptions
An attacker is able to send a specially crafted network packet which causes tcpdump to enter an infinite loop.

Summary

Andrew Griffiths and iDEFENSE Labs discovered a problem in tcpdump, a
powerful tool for network monitoring and data acquisition. An
attacker is able to send a specially crafted network packet which
causes tcpdump to enter an infinite loop.

In addition to the above problem the tcpdump developers discovered a
potential infinite loop when parsing malformed BGP packets. They also
discovered a buffer overflow that can be exploited with certain
malformed NFS packets.

For the stable distribution (woody) these problems have been
fixed in version 3.6.2-2.3.

For the old stable distribution (potato) does not seem to be affected
by this problem.

For the unstable distribution (sid) these problems have been fixed in
version 3.7.1-1.2.

We recommend that you upgrade your tcpdump packages.


Upgrade Instructions
--------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given be...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: tcpdump

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here