CVE-2002-1350Tcpdump vulnerability

9 documents8 sources
Severity
7.5HIGHNVD
EPSS
2.5%
top 14.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 23
Latest updateMay 3

Description

The BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data, which allows remote attackers to cause a denial of service (application crash).

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Debiantcpdump/tcpdump< 3.7.2-1+3
NVDlbl/tcpdump3.6.2.2.2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-r67j-rqm9-w8mr: The BGP decoding routines in tcpdump 32022-05-03
CVEList
CVE-2002-1350: The BGP decoding routines in tcpdump 32004-09-01
OSV
CVE-2002-1350: The BGP decoding routines in tcpdump 32002-12-23

💥Exploits & PoCs

1
Exploit-DB
Fully Modded phpBB - 'kb.php' SQL Injection2008-03-12

📋Vendor Advisories

2
Debian
CVE-2002-1350: tcpdump - The BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data,...2002
Red Hat
security flaw2001-10-15

💬Community

2
Bugzilla
CVE-2002-1350 security flaw2018-08-16
Bugzilla
tcpdump problem with bgp decoding2003-01-29
CVE-2002-1350 — LBL Tcpdump vulnerability | cvebase