The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2004-02-16 21:00
Updated : 2018-10-19 08:29
NVD link : CVE-2003-1029
Mitre link : CVE-2003-1029
JSON object : View
CWE
Products Affected
lbl
- tcpdump