Short Name |
IKE:DOS:TCP-HUMP |
---|---|
Severity |
High |
Recommended |
No |
Category |
IKE |
Keywords |
ike tcphump |
Release Date |
2004/02/02 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This protocol anomaly is a malformed packet designed to exploit a vulnerability in the ISAKMP parsing routines of the tcpdump program. Attackers can send maliciously crafted packets on the network to remotely execute arbitrary code with the privileges of the tcpdump process, causing a denial of service (DoS).
It has been reported that tcpdump may be prone to multiple remote buffer overflow vulnerabilities that may allow an attacker to gain unauthorized access to a system. It has been reported that a remote attacker may be able to cause a buffer overrun condition by sending specially crafted packets to a vulnerable system. Immediate consequences of a successful attack may cause a denial of service condition in the software. The attacker may also be able to execute arbitrary code on a vulnerable system as the 'pcap' user. Some of the issues are reported to affect tcpdump versions prior to 3.8.1 and others reportedly affect all versions up to and including tcpdump 3.8.1. This vulnerability record will be divided into multiple Bugtraq IDs when analysis of the individual issues is complete.