FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0184

This CVE name corresponds to:

Entered Topic
2004-03-31 tcpdump ISAKMP payload handling remote denial-of-service

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0184
Phase Assigned(20040302)

Description

Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.

References

Source Reference
BUGTRAQ 20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities
MISC http://www.rapid7.com/advisories/R7-0017.html
CONFIRM http://www.tcpdump.org/tcpdump-changes.txt
DEBIAN DSA-478
FEDORA FEDORA-2004-1468
REDHAT RHSA-2004:219
TRUSTIX 2004-0015
CERT-VN VU#492558
BID 10004
OVAL oval:org.mitre.oval:def:976
OVAL oval:org.mitre.oval:def:9581
SECTRACK 1009593
SECUNIA 11258
XF tcpdump-isakmp-integer-underflow(15679)