First published: Mon Mar 31 2003(Updated: )
Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tcpdump | =3.5.2 | |
Tcpdump | =3.6.2 | |
Tcpdump | =3.7 | |
Tcpdump | =3.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0145 is rated as a moderate severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2003-0145, upgrade tcpdump to version 3.7.2 or later where the vulnerability has been addressed.
CVE-2003-0145 affects tcpdump versions 3.5.2, 3.6.2, 3.7, and 3.7.1.
CVE-2003-0145 is a denial of service vulnerability related to the handling of unknown RADIUS attributes in tcpdump.
Yes, CVE-2003-0145 can be exploited remotely by sending specially crafted packets that exploit the vulnerability.