PT-2001-1093 · Tcpdump · Tcpdump

Published

2001-11-28

·

Updated

2016-10-18

·

CVE-1999-1024

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Tcpdump version 3.4a
Description The issue allows remote attackers to cause a denial of service via a packet with a zero length header. This results in an infinite loop and core dump when Tcpdump prints the packet.
Recommendations For Tcpdump version 3.4a, consider updating to a newer version that addresses this issue, as the current version is affected by the denial of service vulnerability caused by packets with zero length headers.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1024

Affected Products

Tcpdump