Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-1280Infinite Loop in Tcpdump

12 documents10 sources
Severity
5.0MEDIUMNVD
EPSS
13.6%
top 5.74%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMay 2
Latest updateMay 3

Description

The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiantcpdump/tcpdump< 3.8.3-4+3
NVDlbl/tcpdump3.9.1

🔴Vulnerability Details

3
GHSA
GHSA-325r-4m7w-pcqf: The rsvp_print function in tcpdump 32022-05-03
OSV
CVE-2005-1280: The rsvp_print function in tcpdump 32005-05-02
CVEList
CVE-2005-1280: The rsvp_print function in tcpdump 32005-04-26

💥Exploits & PoCs

2
Exploit-DB
MWChat 6.8 - 'chat.php' SQL Injection2005-05-21
Exploit-DB
Ethereal 0.10.10 / tcpdump 3.9.1 - 'rsvp_print' Infinite Loop Denial of Service2005-04-26

📋Vendor Advisories

3
Ubuntu
tcpdump vulnerabilities2005-05-06
Red Hat
security flaw2005-04-26
Debian
CVE-2005-1280: tcpdump - The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to ...2005

💬Community

1
Bugzilla
CVE-2005-1280 security flaw2018-08-16