First published: Tue Apr 26 2005(Updated: )
tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tcpdump | <=3.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1279 has been classified as a denial of service vulnerability, which can lead to a service interruption.
To fix CVE-2005-1279, upgrade tcpdump to version 3.8.3 or later.
CVE-2005-1279 affects tcpdump versions up to and including 3.8.3.
CVE-2005-1279 is caused by improperly handled BGP and LDP packets.
Yes, CVE-2005-1279 can be exploited remotely by sending crafted BGP or LDP packets.