Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2004:008: tcpdump Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the tcpdump package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2004:008 (tcpdump).
A number of vulnerabilities were discovered in tcpdump versions prior to 3.8.1
that, if fed a maliciously crafted packet, could be exploited to crash tcpdump
or potentially execute arbitrary code with the rights of the user running
tcpdump. These vulnerabilities include:
An infinite loop and memory consumption processing L2TP packets (CVE-2003-1029).
Infinite loops in processing ISAKMP packets (CVE-2003-0989, CVE-2004-0057).
A segmentation fault caused by a RADIUS attribute with a large length value
The updated packages are patched to correct these problem.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:008
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.