Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
______________________________________________________________________________
SuSE Security Announcement
Package: tcpdump
Announcement-ID: SuSE-SA:2000:46
Date: Friday, November 17th, 2000 16:00 MEST
Affected SuSE versions: 6.0, 6.1, 6.2, 6.3, 6.4, 7.0
Vulnerability Type: remote denial of service
Severity (1-10): 6
SuSE default package: yes
Other affected systems: systems using the same versions of tcpdump
and the necessary libraries
Content of this advisory:
1) security vulnerability resolved: tcpdump
problem description, discussion, solution and upgrade information
2) clarification, pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
tcpdump is a widespread network/packet analysis tool, also known as a
packet sniffer, used in unix/unix-like environment.
Several overflowable buffers have been found in SuSE's version of tcpdump
that could allow a remote attacker to crash the local tcpdump process.
Since tcpdump may be used in combination with intrusion detection
systems, a crashed tcpdump process may disable the network monitoring
system as a whole.
The FreeBSD team who found these vulnerabilities also reported that
tcpdump's portion of code that can decode AFS ACL (AFS=Andrew File
System, a network filesystem, ACL=Access Control List) packets is
vulnerable to a (remotely exploitable) buffer overrun attack that
could allow a remote attacker to execute arbitrary commands as root
since the tcpdump program usually requires root privileges to gain
access to the raw network socket.
The versions of tcpdump as shipped with SuSE distributions do not
contain the AFS packet decoding capability and are therefore not
vulnerable to this second form of attack.
A temporary workaround for the tcpdump problems other than not using
tcpdump in the first place does not exist. However, we provide update
packages for the affected SuSE distributions. We recommend an upgrade
using the packages that can be found using the URLs below.
Note: Please note that there is only one source rpm package but two
binary rpm packages. tcpdump*.rpm is the rpm for the tcpdump program,
and libpcapn*.rpm is the packet capture library that is required by
tcpdump at compile time. In order to remove the security vulnerability
in tcpdump, it is necessary to update the tcpdump rpm package only.
The libpcapn package with the static library is provided for
consistency and compatibility because it will be generated if the
binary packages are rebuilt from the source rpm.
To check if your system has the vulnerable package installed, use the
command `rpm -q
Get the latest Linux and open source security news straight to your inbox.