FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0183

This CVE name corresponds to:

Entered Topic
2004-03-31 tcpdump ISAKMP payload handling remote denial-of-service

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0183
Phase Assigned(20040302)

Description

TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.

References

Source Reference
BUGTRAQ 20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities
MISC http://www.rapid7.com/advisories/R7-0017.html
CONFIRM http://www.tcpdump.org/tcpdump-changes.txt
DEBIAN DSA-478
FEDORA FEDORA-2004-1468
REDHAT RHSA-2004:219
TRUSTIX 2004-0015
CERT-VN VU#240790
BID 10003
OVAL oval:org.mitre.oval:def:972
OVAL oval:org.mitre.oval:def:9971
SECTRACK 1009593
SECUNIA 11258
SECUNIA 11320
XF tcpdump-isakmp-delete-bo(15680)