Vulnerability Name:

CVE-2003-1029 (CCN-14046)

Assigned:2003-12-20
Published:2003-12-20
Updated:2018-10-19
Summary:The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: BugTraq Mailing List, Sat Dec 20 2003 - 10:25:22 CST
Remote crash in tcpdump from OpenBSD

Source: CCN
Type: BugTraq Mailing List, Sat Dec 20 2003 - 13:52:18 CST
Re: Remote crash in tcpdump from OpenBSD

Source: MITRE
Type: CNA
CVE-2003-1029

Source: ENGARDE
Type: UNKNOWN
ESA-20040119-002

Source: BUGTRAQ
Type: UNKNOWN
20031220 Remote crash in tcpdump from OpenBSD

Source: BUGTRAQ
Type: UNKNOWN
20031221 Re: Remote crash in tcpdump from OpenBSD

Source: MLIST
Type: UNKNOWN
[tcpdump-workers] 20031224 Seg fault of tcpdump (v 3.8.1 and below) with malformed l2tp packets

Source: CCN
Type: SA10636
tcpdump ISAKMP and RADIUS Packet Handling Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
10636

Source: SECUNIA
Type: UNKNOWN
10652

Source: SECUNIA
Type: UNKNOWN
10668

Source: SECUNIA
Type: UNKNOWN
10718

Source: CCN
Type: SECTRACK ID: 1008748
Tcpdump l2tp_avp_print() Flaw May Let Remote Users Crash the System With Malformed L2TP Packets

Source: DEBIAN
Type: Patch, Vendor Advisory
DSA-425

Source: DEBIAN
Type: DSA-425
tcpdump -- multiple vulnerabilities

Source: MANDRAKE
Type: UNKNOWN
MDKSA-2004:008

Source: CCN
Type: OpenPKG-SA-2004.002
tcpdump

Source: CCN
Type: OSVDB ID: 3556
tcpdump L2TP DoS

Source: BUGTRAQ
Type: UNKNOWN
20040119 [ESA-20040119-002] 'tcpdump' multiple vulnerabilities.

Source: CCN
Type: BID-9263
Tcpdump L2TP Parser Remote Denial of Service Vulnerability

Source: SECTRACK
Type: UNKNOWN
1008748

Source: XF
Type: UNKNOWN
tcpdump-l2tp-dos(14046)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:lbl:tcpdump:3.4:*:*:*:*:*:*:*
  • OR cpe:/a:lbl:tcpdump:3.5:*:*:*:*:*:*:*
  • OR cpe:/a:lbl:tcpdump:3.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:lbl:tcpdump:3.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:lbl:tcpdump:3.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:lbl:tcpdump:3.7:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:openbsd:openbsd:3.3:*:*:*:*:*:*:*
  • OR cpe:/o:openbsd:openbsd:current:*:*:*:*:*:*:*
  • AND
  • cpe:/o:debian:debian_linux:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:openpkg:openpkg:current:*:*:*:*:*:*:*
  • OR cpe:/a:mandrakesoft:mandrake_multi_network_firewall:8.2:*:*:*:*:*:*:*
  • OR cpe:/a:openpkg:openpkg:1.2:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.1:*:*:*:*:*:*:*
  • OR cpe:/a:openpkg:openpkg:1.3:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.2:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.1::ppc:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.2::amd64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1::x86_64:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20031029
    V
    CVE-2003-1029
    2015-11-16
    oval:org.debian:def:425
    V
    multiple vulnerabilities
    2004-01-16
    BACK
    lbl tcpdump 3.4
    lbl tcpdump 3.5
    lbl tcpdump 3.5.2
    lbl tcpdump 3.6.2
    lbl tcpdump 3.6.3
    lbl tcpdump 3.7
    openbsd openbsd 3.3
    openbsd openbsd current
    debian debian linux 3.0
    openpkg openpkg current
    mandrakesoft mandrake multi network firewall 8.2
    openpkg openpkg 1.2
    mandrakesoft mandrake linux corporate server 2.1
    mandrakesoft mandrake linux 9.1
    openpkg openpkg 1.3
    mandrakesoft mandrake linux 9.2
    mandrakesoft mandrake linux 9.1
    mandrakesoft mandrake linux 9.2
    mandrakesoft mandrake linux corporate server 2.1