CVE-2004-0057Tcpdump vulnerability

10 documents7 sources
Severity
5.0MEDIUMNVD
CNA7.5OSV7.5
EPSS
26.2%
top 3.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 17
Latest updateMay 3

Description

The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiantcpdump/tcpdump< 3.8.3-1+3
NVDlbl/tcpdump3.8.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fmg4-pw8h-q4xp: The rawprint function in the ISAKMP decoding routines (print-isakmp2022-05-03
OSV
CVE-2004-0057: The rawprint function in the ISAKMP decoding routines (print-isakmp2004-02-17
CVEList
CVE-2004-0057: The rawprint function in the ISAKMP decoding routines (print-isakmp2004-01-15

📋Vendor Advisories

3
Red Hat
security flaw2004-01-14
Red Hat
security flaw2004-01-04
Debian
CVE-2004-0057: tcpdump - The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdu...2004

💬Community

3
Bugzilla
CVE-2004-0057 security flaw2018-08-16
Bugzilla
CVE-2003-0989 security flaw2018-08-16
Bugzilla
CAN-2004-0055 CAN-2004-0057 Two issues found in tpcdump2004-01-13
CVE-2004-0057 — LBL Tcpdump vulnerability | cvebase