CVE Vulnerabilities

CVE-2005-1267

Published: Jun 10, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.

Affected Software

NameVendorStart VersionEnd Version
TcpdumpLbl3.4 (including)3.4 (including)
TcpdumpLbl3.4a6 (including)3.4a6 (including)
TcpdumpLbl3.5 (including)3.5 (including)
TcpdumpLbl3.5.2 (including)3.5.2 (including)
TcpdumpLbl3.5_alpha (including)3.5_alpha (including)
TcpdumpLbl3.6.2 (including)3.6.2 (including)
TcpdumpLbl3.6.3 (including)3.6.3 (including)
TcpdumpLbl3.7 (including)3.7 (including)
TcpdumpLbl3.7.1 (including)3.7.1 (including)
TcpdumpLbl3.7.2 (including)3.7.2 (including)
TcpdumpLbl3.8.1 (including)3.8.1 (including)
TcpdumpLbl3.8.2 (including)3.8.2 (including)
TcpdumpLbl3.8.3 (including)3.8.3 (including)
TcpdumpLbl3.9 (including)3.9 (including)
TcpdumpLbl3.9.1 (including)3.9.1 (including)
Red Hat Enterprise Linux 4RedHattcpdump-14:3.8.2-10.RHEL4*

References