PT-2002-1046 · Arpwatch+2 · Arpwatch+2
Published
2002-12-23
·
Updated
2018-05-03
·
CVE-2002-1350
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
tcpdump versions 3.6.x through 3.7
libpcap version 0.6.2
tcpdump version 3.6.3
arpwatch version 2.1a11
Description
The issue affects the BGP decoding routines in tcpdump, allowing remote attackers to cause a denial of service, such as an application crash. Multiple vulnerabilities in libpcap, tcpdump, and arpwatch packages may lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations
For tcpdump versions 3.6.x through 3.7, update to version 3.7 or later.
For libpcap version 0.6.2, update to a newer version that contains a fix for this issue.
For tcpdump version 3.6.3, update to a newer version that contains a fix for this issue.
For arpwatch version 2.1a11, update to a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Arpwatch
Libpcap
Tcpdump