PT-2002-1046 · Arpwatch+2 · Arpwatch+2

Published

2002-12-23

·

Updated

2018-05-03

·

CVE-2002-1350

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions tcpdump versions 3.6.x through 3.7 libpcap version 0.6.2 tcpdump version 3.6.3 arpwatch version 2.1a11
Description The issue affects the BGP decoding routines in tcpdump, allowing remote attackers to cause a denial of service, such as an application crash. Multiple vulnerabilities in libpcap, tcpdump, and arpwatch packages may lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For tcpdump versions 3.6.x through 3.7, update to version 3.7 or later. For libpcap version 0.6.2, update to a newer version that contains a fix for this issue. For tcpdump version 3.6.3, update to a newer version that contains a fix for this issue. For arpwatch version 2.1a11, update to a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07981
BDU:2015-08151
BDU:2015-08224
CVE-2002-1350
DSA-206

Affected Products

Arpwatch
Libpcap
Tcpdump