CVE-2004-0055Tcpdump vulnerability

8 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
33.7%
top 3.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 17
Latest updateMay 3

Description

The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiantcpdump/tcpdump< 3.8.3-1+3
NVDlbl/tcpdump4 versions+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-73vp-66j6-8j69: The print_attr_string function in print-radius2022-05-03
OSV
CVE-2004-0055: The print_attr_string function in print-radius2004-02-17
CVEList
CVE-2004-0055: The print_attr_string function in print-radius2004-01-15

📋Vendor Advisories

2
Red Hat
security flaw2004-01-04
Debian
CVE-2004-0055: tcpdump - The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier a...2004

💬Community

2
Bugzilla
CVE-2004-0055 security flaw2018-08-16
Bugzilla
CAN-2004-0055 CAN-2004-0057 Two issues found in tpcdump2004-01-13
CVE-2004-0055 — LBL Tcpdump vulnerability | cvebase