CVE-2005-1267
tcpdump - infinite loop
EPSS 11.3%
Description
The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.
How to fix CVE-2005-1267
To remediate CVE-2005-1267, upgrade the affected package to a fixed version below.
- Debian/tcpdump—upgrade to 3.9.0.cvs.20050614-1 or later
- Debian/tcpdump—upgrade to 3.8.3-5sarge1 or later
Is CVE-2005-1267 being exploited?
Moderate — EPSS is 11.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 3.9.0.cvs.20050614-1
- from 0, < 3.8.3-5sarge1