CVE-2003-1029
CVE-2003-1029
The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/23452unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lwn.net/Alerts/66805/http://marc.info/?l=bugtraq&m=107193841728533&w=2http://marc.info/?l=bugtraq&m=107213553214985&w=2http://marc.info/?l=tcpdump-workers&m=107228187124962&w=2http://secunia.com/advisories/10636http://secunia.com/advisories/10652http://secunia.com/advisories/10668http://secunia.com/advisories/10718http://www.debian.org/security/2004/dsa-425http://www.mandriva.com/security/advisories?name=MDKSA-2004:008http://www.securityfocus.com/archive/1/350238/30/21640/threadedhttp://www.securitytracker.com/id?1008748