Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2004:030: tcpdump Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the tcpdump package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2004:030 (tcpdump).
A number of vulnerabilities were discovered in tcpdump versions prior to 3.8.1
that, if fed a maliciously crafted packet, could be exploited to crash tcpdump.
These vulnerabilities include:
Remote attackers can cause a denial of service (crash) via ISAKMP packets
containing a Delete payload with a large number of SPI's, which causes an
out-of-bounds read. (CVE-2004-1083)
Integer underflow in the isakmp_id_print allows remote attackers to cause a
denial of service (crash) via an ISAKMP packet with an Identification payload
with a length that becomes less than 8 during byte order conversion, which
causes an out-of-bounds read. (CVE-2004-0184)
The updated packages are patched to correct these problems.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:030
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.