CVE-2003-1029 – Tcpdump 3.x - L2TP Parser Remote Denial of Service
https://notcve.org/view.php?id=CVE-2003-1029
The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets. El procesador (parser) del protocolo L2TP en tcpdump 3.8.1 y anteriores permite a atacantes remotos causar una denegación de servicio (bucle infinito y consumición de memoria) mediante un paquete con datos no válidos al puerto UDP 1701, lo que causa que l2tp_avp_print ustilice un valor de longitud malo cuando llama a print_octets() • https://www.exploit-db.com/exploits/23452 http://lwn.net/Alerts/66805 http://marc.info/?l=bugtraq&m=107193841728533&w=2 http://marc.info/?l=bugtraq&m=107213553214985&w=2 http://marc.info/?l=tcpdump-workers&m=107228187124962&w=2 http://secunia.com/advisories/10636 http://secunia.com/advisories/10652 http://secunia.com/advisories/10668 http://secunia.com/advisories/10718 http://www.debian.org/security/2004/dsa-425 http://www.mandriva.com/security/advisories?na •
CVE-2004-0055
https://notcve.org/view.php?id=CVE-2004-0055
The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value. La función print_attr_string en print-radius.c de tcpdump 3.8.1 y anteriores permite a atacantes remotos causar una denegación de servicio (fallo de segmentación) mediante un atributo RADIUS con un valor de longitud demasiado grande. • ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000832 http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html http://lwn.net/Alerts/66445 http://marc.info/?l=b •
CVE-2003-0145
https://notcve.org/view.php?id=CVE-2003-0145
Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093. • http://www.debian.org/security/2003/dsa-261 http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027 http://www.redhat.com/support/errata/RHSA-2003-032.html http://www.redhat.com/support/errata/RHSA-2003-151.html http://www.redhat.com/support/errata/RHSA-2003-214.html http://www.tcpdump.org/tcpdump-changes.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/11857 https://access.redhat.com/security/cve/CVE-2003-0145 https://bugzilla.redhat.com/show_bug.cgi?i •
CVE-2003-0108 – TCPDump 3.x - Malformed ISAKMP Packet Denial of Service
https://notcve.org/view.php?id=CVE-2003-0108
isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop. isakmp_sub_print en tcpdump 3.6 a la 3.7.1 permite a atacantes remotos causar Denegación de Servicio (consumo de CPU) mediante cierto paquete ISAKMP malformado enviado al puerto 500 UDP, lo que provoca que tcpdump entre en un bucle infinito. • https://www.exploit-db.com/exploits/22294 http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000629 http://marc.info/?l=bugtraq&m=104637420104189&w=2 http://marc.info/?l=bugtraq&m=104678787109030&w=2 http://www.debian.org/security/2003/dsa-255 http://www.idefense.com/advisory/02.27.03.txt http://www.iss.net/security_center/static/11434.php http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027 http://www.novell.com/linux/security/advisories/2 •
CVE-2003-0093
https://notcve.org/view.php?id=CVE-2003-0093
The RADIUS decoder in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service (crash) via an invalid RADIUS packet with a header length field of 0, which causes tcpdump to generate data within an infinite loop. • http://www.debian.org/security/2003/dsa-261 http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027 http://www.redhat.com/support/errata/RHSA-2003-032.html http://www.redhat.com/support/errata/RHSA-2003-033.html http://www.redhat.com/support/errata/RHSA-2003-214.html https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585 https://exchange.xforce.ibmcloud.com/vulnerabilities/11324 https://access.redhat.com/security/cve/CVE-2003-0093 https://bugzilla.redhat.com •