Vulnerability Name: | CVE-2001-1279 (CCN-7006) | ||||||||
Assigned: | 2001-07-17 | ||||||||
Published: | 2001-07-17 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | Buffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code via AFS RPC packets with invalid lengths that trigger an integer signedness error, a different vulnerability than CVE-2000-1026. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CALDERA Type: UNKNOWN CSSA-2002-025.0 Source: CCN Type: Caldera International, Inc. Security Advisory CSSA-2002-025.0 Linux: tcpdump AFS RPC and NFS packet vulnerabilities Source: CCN Type: FreeBSD Security Advisory FreeBSD-SA-01:48 tcpdump contains remote buffer overflow Source: FREEBSD Type: UNKNOWN FreeBSD-SA-01:48 Source: MITRE Type: CNA CVE-2001-1279 Source: CONECTIVA Type: UNKNOWN CLA-2002:480 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2002:480 tcpdump Source: CCN Type: RHSA-2001-089 Updated tcpdump packages available for Red Hat Linux 6.2 and 7.x Source: CCN Type: CIAC Information Bulletin L-122 FreeBSD tcpdump Remote Buffer Overflow Vulnerability Source: XF Type: UNKNOWN tcpdump-afs-rpc-bo(7006) Source: CCN Type: US-CERT VU#797201 tcpdump vulnerable to buffer overflow via improper decoding of AFS RPC (Rx) packets Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#797201 Source: MANDRAKE Type: UNKNOWN MDKSA-2002:032 Source: REDHAT Type: Patch, Vendor Advisory RHSA-2001:089 Source: BID Type: UNKNOWN 3065 Source: CCN Type: BID-3065 TCPDump AFS Signed Integer Buffer Overflow Vulnerability Source: XF Type: UNKNOWN tcpdump-afs-rpc-bo(7006) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |