tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ethereal | Ethereal_group | 0.8.4 (including) | 0.8.4 (including) |
Ethereal | Ethereal_group | 0.8.5 (including) | 0.8.5 (including) |
Ethereal | Ethereal_group | 0.8.6 (including) | 0.8.6 (including) |
Tcpdump | Lbl | 3.4 (including) | 3.4 (including) |
Tcpdump | Lbl | 3.5a (including) | 3.5a (including) |