Gentoo Linux Security Advisory GLSA 200707-14
https://security.gentoo.org/
Severity: High
Title: tcpdump: Integer overflow
Date: July 28, 2007
Bugs: #184815
ID: 200707-14
Synopsis
=======
A vulnerability has been discovered in tcpdump, allowing for the
execution of arbitrary code, possibly with root privileges.
Background
=========
tcpdump is a tool for capturing and inspecting network traffic.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-analyzer/tcpdump < 3.9.5-r3 >= 3.9.5-r3
==========
mu-b from Digital Labs discovered that the return value of a snprintf()
call is not properly checked before being used. This could lead to an
integer overflow.
Impact
===...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.