Gentoo: tcpdump denial of service
Summary
- - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200303-5 - - ---------------------------------------------------------------------
- - ---------------------------------------------------------------------
- From advisory:
"A vulnerability exists in the parsing of ISAKMP packets (UDP port 500) that allows an attacker to force TCPDUMP into an infinite loop upon receipt of a specially crafted packet."
Read the full advisory at: /us-en
SOLUTION
It is recommended that all Gentoo Linux users who are running net-analyzer/tcpdump upgrade to tcpdump-3.7.2 as follows:
emerge sync emerge -u tcpdump emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - ---------------------------------------------------------------------
3.7.2