Summary
The remote host is missing updates announced in
advisory GLSA 200505-06.
Solution
All TCPDump users should upgrade to the latest available version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=net-analyzer/tcpdump-3.8.3-r3'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200505-06 http://bugs.gentoo.org/show_bug.cgi?id=90541
http://bugs.gentoo.org/show_bug.cgi?id=95349
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2005-1267 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2005-1278 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2005-1279 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2005-1280
Insight
A flaw in the decoding of network packets renders TCPDump vulnerable to a remote Denial of Service attack.
Severity
Classification
-
CVE CVE-2005-1267, CVE-2005-1278, CVE-2005-1279, CVE-2005-1280 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities