IKE: TCP Hump

This protocol anomaly is a malformed packet designed to exploit a vulnerability in the ISAKMP parsing routines of the tcpdump program. Attackers can send maliciously crafted packets on the network to remotely execute arbitrary code with the privileges of the tcpdump process, causing a denial of service (DoS).

Extended Description

It has been reported that tcpdump may be prone to multiple remote buffer overflow vulnerabilities that may allow an attacker to gain unauthorized access to a system. It has been reported that a remote attacker may be able to cause a buffer overrun condition by sending specially crafted packets to a vulnerable system. Immediate consequences of a successful attack may cause a denial of service condition in the software. The attacker may also be able to execute arbitrary code on a vulnerable system as the 'pcap' user. Some of the issues are reported to affect tcpdump versions prior to 3.8.1 and others reportedly affect all versions up to and including tcpdump 3.8.1. This vulnerability record will be divided into multiple Bugtraq IDs when analysis of the individual issues is complete.

Affected Products

Lbl tcpdump

Short Name
IKE:DOS:TCP-HUMP
Severity
Major
Recommended
False
Recommended Action
None
Category
IKE
Keywords
CVE-2004-0057 bid:9423 ike tcphump
Release Date
02/02/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Red_hat

Sgi

Sco

Lbl

Apple

CVSS Score

5.0

Found a potential security threat?