FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

tcpdump -- infinite loops in protocol decoding

Affected packages
5.4 <= FreeBSD < 5.4_2
5.3 <= FreeBSD < 5.3_16
tcpdump < 3.8.3_2

Details

VuXML ID 9fae0f1f-df82-11d9-b875-0001020eed82
Discovery 2005-06-09
Entry 2005-06-18
Modified 2005-06-20

Problem Description

Several tcpdump protocol decoders contain programming errors which can cause them to go into infinite loops.

Impact

An attacker can inject specially crafted packets into the network which, when processed by tcpdump, could lead to a denial-of-service. After the attack, tcpdump would no longer capture traffic, and would potentially use all available processor time.

References

CVE Name CVE-2005-1267
CVE Name CVE-2005-1278
CVE Name CVE-2005-1279
CVE Name CVE-2005-1280
FreeBSD Advisory SA-05:10.tcpdump
Message 20050426100140.1945.qmail@www.securityfocus.com
Message 20050426100057.1748.qmail@www.securityfocus.com
Message 20050619091553.GB982@zaphod.nitro.dk