Summary
The remote host is missing an update to tcpdump
announced via advisory DSA 478-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20478-1
Insight
tcpdump, a tool for network monitoring and data acquisition, was found to contain two vulnerabilities whereby tcpdump could be caused to crash through attempts to read from invalid memory locations. This bug is triggered by certain invalid ISAKMP packets.
For the current stable distribution (woody) these problems have been fixed in version 3.6.2-2.8.
For the unstable distribution (sid), these problems have been fixed in version 3.7.2-4.
We recommend that you update your tcpdump package.
Severity
Classification
-
CVE CVE-2004-0183, CVE-2004-0184 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities