PT-2003-1074 · Arpwatch+3 · Arpwatch+3

Phil Meek

·

Published

2003-03-03

·

Updated

2017-10-10

·

CVE-2003-0093

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions tcpdump versions 3.6.2 and earlier libpcap version 0.6.2 arpwatch version 2.1a11
Description The issue concerns multiple vulnerabilities in certain packages of the Red Hat Linux operating system, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. Specifically, the RADIUS decoder in tcpdump is vulnerable to a denial of service attack via an invalid RADIUS packet with a header length field of 0, causing tcpdump to enter an infinite loop.
Recommendations For tcpdump versions 3.6.2 and earlier, consider updating to a version later than 3.6.2 to resolve the issue. For libpcap version 0.6.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For arpwatch version 2.1a11, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07981
BDU:2015-08151
BDU:2015-08224
CVE-2003-0093
DSA-261

Affected Products

Red Hat
Arpwatch
Libpcap
Tcpdump