Re: [Full-Disclosure] Security Update: [CSSA-2002-050.0] Linux: tcpdump denial-of-service in print-bgp.c

From: Silvio Cesare (silvioat_private)
Date: Tue Nov 19 2002 - 21:30:23 PST

  • Next message: Peter Bieringer: "[Full-Disclosure] Opera 6.03/Linux crashes on HTTPS over Squid Proxy on a site"

    Also, one quick addition to this; this problem effects all tcpdump, and is not
    OpenLinux (or even Linux) specific.
    
    It is recommended that ALL distro's upgrade their packages to the latest,
    which has long resolved the specific problem this advisory is
    reporting.
    
    Anyway.. nice advisory ;-)
    
    --
    Silvio
    
    On Tue, Nov 19, 2002 at 03:55:31PM -0800, securityat_private wrote:
    > To: bugtraqat_private announceat_private security-alertsat_private full-disclosureat_private
    > 
    > ______________________________________________________________________________
    > 
    > 			SCO Security Advisory
    > 
    > Subject:		Linux: tcpdump denial-of-service in print-bgp.c 
    > Advisory number: 	CSSA-2002-050.0
    > Issue date: 		2002 November 19
    > Cross reference:
    > ______________________________________________________________________________
    > 
    > 
    > 1. Problem Description
    > 
    > 	There is a miscalculation in the use of the sizeof operator in
    > 	tcpdump, allowing, at the least, a denial-of-service attack.
    > 
    > 
    > 2. Vulnerable Supported Versions
    > 
    > 	System				Package
    > 	----------------------------------------------------------------------
    > 
    > 	OpenLinux 3.1.1 Server		prior to tcpdump-3.6.2-4.i386.rpm
    > 
    > 	OpenLinux 3.1.1 Workstation	prior to tcpdump-3.6.2-4.i386.rpm
    > 
    > 	OpenLinux 3.1 Server		prior to tcpdump-3.6.2-4.i386.rpm
    > 
    > 	OpenLinux 3.1 Workstation	prior to tcpdump-3.6.2-4.i386.rpm
    > 
    > 
    > 3. Solution
    > 
    > 	The proper solution is to install the latest packages. Many
    > 	customers find it easier to use the Caldera System Updater, called
    > 	cupdate (or kcupdate under the KDE environment), to update these
    > 	packages rather than downloading and installing them by hand.
    
    --
    Silvio
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    



    This archive was generated by hypermail 2b30 : Wed Nov 20 2002 - 14:14:16 PST