CVE-2005-1267
medium · 5The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.
5
CVSS
13.5%
EPSS (exploit prob.)
96th
EPSS percentile
2005-06-10
Published
AV:N/AC:L/Au:N/C:N/I:N/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| lbl | tcpdump | 3.4 |
| lbl | tcpdump | 3.4a6 |
| lbl | tcpdump | 3.5 |
| lbl | tcpdump | 3.5.2 |
| lbl | tcpdump | 3.5_alpha |
| lbl | tcpdump | 3.6.2 |
| lbl | tcpdump | 3.6.3 |
| lbl | tcpdump | 3.7 |
| lbl | tcpdump | 3.7.1 |
| lbl | tcpdump | 3.7.2 |
| lbl | tcpdump | 3.8.1 |
| lbl | tcpdump | 3.8.2 |
| lbl | tcpdump | 3.8.3 |
| lbl | tcpdump | 3.9 |
| lbl | tcpdump | 3.9.1 |
| gentoo | linux | all versions |
| mandrakesoft | mandrake_linux | 10.1 |
| mandrakesoft | mandrake_linux | 10.1 |
| mandrakesoft | mandrake_linux | 10.2 |
| mandrakesoft | mandrake_linux | 10.2 |
| redhat | fedora_core | core_3.0 |
| redhat | fedora_core | core_4.0 |
| trustix | secure_linux | 2.0 |
| trustix | secure_linux | 2.1 |
| trustix | secure_linux | 2.2 |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/15634/
- http://secunia.com/advisories/17118
- http://www.debian.org/security/2005/dsa-854
- http://www.redhat.com/archives/fedora-announce-list/2005-June/msg00007.html
- http://www.redhat.com/support/errata/RHSA-2005-505.html
- http://www.securityfocus.com/archive/1/430292/100/0/threaded
- http://www.securityfocus.com/bid/13906
- http://www.trustix.org/errata/2005/0028/
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=159208
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11148
- http://secunia.com/advisories/15634/
- http://secunia.com/advisories/17118
- http://www.debian.org/security/2005/dsa-854
- http://www.redhat.com/archives/fedora-announce-list/2005-June/msg00007.html
- http://www.redhat.com/support/errata/RHSA-2005-505.html
- http://www.securityfocus.com/archive/1/430292/100/0/threaded
- http://www.securityfocus.com/bid/13906
- http://www.trustix.org/errata/2005/0028/
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=159208
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11148
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2005-1267