First published: Tue Apr 26 2005(Updated: )
The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tcpdump | <=3.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1278 has a severity rating that indicates it can lead to a denial of service due to an infinite loop.
To fix CVE-2005-1278, upgrade tcpdump to version 3.9.2 or later.
CVE-2005-1278 affects tcpdump versions up to and including 3.9.1.
CVE-2005-1278 facilitates a denial of service attack that can be executed via a zero-length GRE packet.
There are no recommended workarounds for CVE-2005-1278; upgrading the software is advised.