GLSA-200404-03 : Tcpdump Vulnerabilities in ISAKMP Parsing

This script is Copyright (C) 2004-2014 Tenable Network Security, Inc.


Synopsis :

The remote Gentoo host is missing one or more security-related
patches.

Description :

The remote host is affected by the vulnerability described in GLSA-200404-03
(Tcpdump Vulnerabilities in ISAKMP Parsing)

There are two specific vulnerabilities in tcpdump, outlined in [ reference
1 ]. In the first scenario, an attacker may send a specially-crafted ISAKMP
Delete packet which causes tcpdump to read past the end of its buffer. In
the second scenario, an attacker may send an ISAKMP packet with the wrong
payload length, again causing tcpdump to read past the end of a buffer.

Impact :

Remote attackers could potentially cause tcpdump to crash or execute
arbitrary code as the 'pcap' user.

Workaround :

There is no known workaround at this time. All tcpdump users are encouraged
to upgrade to the latest available version.

See also :

http://www.rapid7.com/advisories/R7-0017.html
http://rhn.redhat.com/errata/RHSA-2004-008.html
http://www.gentoo.org/security/en/glsa/glsa-200404-03.xml

Solution :

All tcpdump users should upgrade to the latest available version.
ADDITIONALLY, the net-libs/libpcap package should be upgraded.
# emerge sync
# emerge -pv '>=net-libs/libpcap-0.8.3-r1' '>=net-analyzer/tcpdump-3.8.3-r1'
# emerge '>=net-libs/libpcap-0.8.3-r1' '>=net-analyzer/tcpdump-3.8.3-r1'

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)

Family: Gentoo Local Security Checks

Nessus Plugin ID: 14468 (gentoo_GLSA-200404-03.nasl)

Bugtraq ID:

CVE ID: CVE-2003-0989