CVE
- Id
- 8611
- CVE No.
- CVE-2004-0183
- Status
- Candidate
- Description
- TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI"s, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.
- Phase
- Assigned (20040302)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
53769 | 8611 | CVE-2004-0183 | BUGTRAQ:20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities | View |
53770 | 8611 | CVE-2004-0183 | URL:http://marc.info/?l=bugtraq&m=108067265931525&w=2 | View |
53771 | 8611 | CVE-2004-0183 | MISC:http://www.rapid7.com/advisories/R7-0017.html | View |
53772 | 8611 | CVE-2004-0183 | CONFIRM:http://www.tcpdump.org/tcpdump-changes.txt | View |
53773 | 8611 | CVE-2004-0183 | DEBIAN:DSA-478 | View |
53774 | 8611 | CVE-2004-0183 | URL:http://www.debian.org/security/2004/dsa-478 | View |
53775 | 8611 | CVE-2004-0183 | FEDORA:FEDORA-2004-1468 | View |
53776 | 8611 | CVE-2004-0183 | URL:https://bugzilla.fedora.us/show_bug.cgi?id=1468 | View |
53777 | 8611 | CVE-2004-0183 | REDHAT:RHSA-2004:219 | View |
53778 | 8611 | CVE-2004-0183 | URL:http://www.redhat.com/support/errata/RHSA-2004-219.html | View |
53779 | 8611 | CVE-2004-0183 | TRUSTIX:2004-0015 | View |
53780 | 8611 | CVE-2004-0183 | URL:http://www.trustix.org/errata/2004/0015 | View |
53781 | 8611 | CVE-2004-0183 | CERT-VN:VU#240790 | View |
53782 | 8611 | CVE-2004-0183 | URL:http://www.kb.cert.org/vuls/id/240790 | View |
53783 | 8611 | CVE-2004-0183 | BID:10003 | View |
53784 | 8611 | CVE-2004-0183 | URL:http://www.securityfocus.com/bid/10003 | View |
53785 | 8611 | CVE-2004-0183 | OVAL:oval:org.mitre.oval:def:972 | View |
53786 | 8611 | CVE-2004-0183 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:972 | View |
53787 | 8611 | CVE-2004-0183 | OVAL:oval:org.mitre.oval:def:9971 | View |
53788 | 8611 | CVE-2004-0183 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9971 | View |
53789 | 8611 | CVE-2004-0183 | SECTRACK:1009593 | View |
53790 | 8611 | CVE-2004-0183 | URL:http://securitytracker.com/id?1009593 | View |
53791 | 8611 | CVE-2004-0183 | SECUNIA:11258 | View |
53792 | 8611 | CVE-2004-0183 | URL:http://secunia.com/advisories/11258 | View |
53793 | 8611 | CVE-2004-0183 | SECUNIA:11320 | View |
53794 | 8611 | CVE-2004-0183 | URL:http://secunia.com/advisories/11320 | View |
53795 | 8611 | CVE-2004-0183 | XF:tcpdump-isakmp-delete-bo(15680) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
62765 | JVNDB-2004-000106 | tcpdump の isakmp_id_print() 関数におけるサービス運用妨害 (DoS) の脆弱性 | tcpdump には、isakmp_id_print() 関数において ISAKMP ID ペイロードのペイロード長の取り扱いに不備が存在し、キャプチャするパケット長を 325 byte 以上に設定している場合に細工された ISAKMP パケットを処理することで tcpdump がクラッシュする脆弱性が存在します。なお、本脆弱性は -v オプションを指定してパケットの冗長表示を有効にしている場合にのみ再現します。 | CVE-2004-0184 | 8611 | 5 | http://jvndb.jvn.jp/ja/contents/2004/JVNDB-2004-000106.html | View |