LWN.net Logo

Multiple vulnerabilities in tcpdump

Package(s):tcpdump CVE #(s):
Created:May 21, 2002 Updated:June 5, 2002
Description: Version 3.5.2 fixed a buffer overflow vulnerability in all prior versions. However, newer versions, including 3.6.2, are vulnerable to another buffer overflow in the AFS RPC functions that was reported by Nick Cleaton. (First LWN report: May 9).

Both problems appear to have been reported and fixed in FreeBSD some months ago. The CIAC report on the vulnerability in versions prior to 3.5.2 is dated October 31, 2000. Nick Cleaton's FreeBSD security advisory on the AFS RPC bug, and reference to a fix for FreeBSD, is dated July, 17, 2001. Tcpdump 3.7 was released on January 21, 2002.

Alerts:
SuSE SuSE-SA:2002:020 2002-05-29
Red Hat RHSA-2001:089-08 2002-02-12
Mandrake MDKSA-2002:032 2002-05-16
Conectiva CLA-2002:480 2002-05-07

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds