FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-1267

This CVE name corresponds to:

Entered Topic
2005-06-18 tcpdump -- infinite loops in protocol decoding

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-1267
Phase Assigned(20050425)

Description

The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.

References

Source Reference
MISC https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=159208
DEBIAN DSA-854
FEDORA FEDORA-2005-406
FEDORA FLSA:156139
REDHAT RHSA-2005:505
TRUSTIX 2005-0028
BID 13906
OVAL oval:org.mitre.oval:def:11148
SECUNIA 15634
SECUNIA 17118