Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian: DSA-206-1 Moderate: Tcpdump Denial of Service Risk

debian
Calendar Grey December 11, 2002
Debian Logo
The advisory DSA-206-1 for Debian addresses a vulnerability in tcpdump associated with inadequate boundary checks, posing risks of denial of service and potential remote code execution.
The BGP decoding routines for tcpdump used incorrect bounds checking when copying data

Summary

Package : tcpdump
Problem type : incorrect bounds checking
Debian-specific: no

The BGP decoding routines for tcpdump used incorrect bounds checking
when copying data. This could be abused by introducing malicious traffic
on a sniffed network for a denial of service attack against tcpdump,
or possibly even remote code execution.

This has been fixed in version 3.6.2-2.2.


------------------------------------------------------------------------

Obtaining updates:

By hand:
wget URL
will fetch the file for you.
dpkg -i FILENAME.deb
will install the fetched file.

With apt:
deb Debian -- Security Information stable/updates main
added to /etc/apt/sources.list will provide security updates

Additional information can be found on the Debian security webpages
at Debian -- Security Information

------------------------------------------------------------------------


Debian GNU/Linux 3.0 alias woody
--------------------------------

Woody was released for alpha, arm, ...

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here