First published: Tue Apr 26 2005(Updated: )
The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tcpdump | <=3.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1280 is a denial of service vulnerability with a high severity that can cause tcpdump to enter an infinite loop.
To fix CVE-2005-1280, upgrade tcpdump to version 3.9.2 or later.
CVE-2005-1280 affects tcpdump versions up to and including 3.9.1.
The impact of CVE-2005-1280 is that it allows remote attackers to cause a denial of service, rendering the tcpdump utility unusable.
Yes, CVE-2005-1280 is remotely exploitable through a crafted RSVP packet.