FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-3798

This CVE name corresponds to:

Entered Topic
2007-08-02 FreeBSD -- Buffer overflow in tcpdump(1)

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-3798
Phase Assigned(20070716)

Description

Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.

References

Source Reference
BUGTRAQ 20070720 rPSA-2007-0147-1 tcpdump
MISC http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-bgp.c?r1=1.91.2.11&r2=1.91.2.12
MISC http://www.digit-labs.org/files/exploits/private/tcpdump-bgp.c
CONFIRM http://bugs.gentoo.org/show_bug.cgi?id=184815
CONFIRM http://docs.info.apple.com/article.html?artnum=307179
APPLE APPLE-SA-2007-12-17
DEBIAN DSA-1353
FREEBSD FreeBSD-SA-07:06
GENTOO GLSA-200707-14
MANDRIVA MDKSA-2007:148
REDHAT RHSA-2007:0368
REDHAT RHSA-2007:0387
SLACKWARE SSA:2007-230-01
SUSE SUSE-SR:2007:016
TRUSTIX 2007-0023
TURBO TLSA-2007-46
UBUNTU USN-492-1
CERT TA07-352A
BID 24965
OVAL oval:org.mitre.oval:def:9771
VUPEN ADV-2007-2578
VUPEN ADV-2007-4238
SECTRACK 1018434
SECUNIA 26135
SECUNIA 26168
SECUNIA 26223
SECUNIA 26266
SECUNIA 26231
SECUNIA 26286
SECUNIA 26263
SECUNIA 26404
SECUNIA 26395
SECUNIA 26521
SECUNIA 27580
SECUNIA 28136