tcpdump Print-bgp.C Remote Integer Underflow Vulnerability
BID:24965
Info
tcpdump Print-bgp.C Remote Integer Underflow Vulnerability
| Bugtraq ID: | 24965 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3798 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2007 12:00AM |
| Updated: | Mar 19 2015 08:27AM |
| Credit: | mu-b of digit-labs.org discovered this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 x86 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 10.0.0 x64 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux FUJI Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Turbolinux FUJI 0 Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 2.0 Trustix Secure Linux 3.0.5 Trustix Secure Linux 3.0 Trustix Secure Linux 2.0 Trustix Operating System Enterprise Server 2.0 tcpdump tcpdump 3.9.6 tcpdump tcpdump 3.9.4 tcpdump tcpdump 3.9.1 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 7 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 12.0 Slackware Linux 11.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 7.3 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Desktop 10 S.u.S.E. LINUX 9.1 Personal Edition CD-ROM S.u.S.E. Linux 8.1 S.u.S.E. Linux 8.0 S.u.S.E. Linux 7.3 S.u.S.E. Linux 7.2 S.u.S.E. Linux 7.1 S.u.S.E. Linux 7.0 S.u.S.E. Linux 6.4 S.u.S.E. Linux 6.3 S.u.S.E. Linux 6.2 S.u.S.E. Linux 6.1 S.u.S.E. Linux 6.0 S.u.S.E. Linux 5.3 S.u.S.E. Linux 5.2 S.u.S.E. Linux 5.1 S.u.S.E. Linux 5.0 S.u.S.E. Linux 4.4.1 S.u.S.E. Linux 4.4 S.u.S.E. Linux 4.3 S.u.S.E. Linux 4.2 S.u.S.E. Linux 4.0 S.u.S.E. Linux 3.0 S.u.S.E. Linux 2.0 S.u.S.E. Linux 1.0 S.u.S.E. Linux 9.3 x86-64 S.u.S.E. Linux 9.3 x86 rPath rPath Linux 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Desktop 4.0 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server NetBSD NetBSD Current NetBSD NetBSD 4.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Gentoo Linux FreeBSD FreeBSD 6.0 .x FreeBSD FreeBSD 6.0 -STABLE FreeBSD FreeBSD 6.0 -RELEASE FreeBSD FreeBSD 5.5 -STABLE FreeBSD FreeBSD 5.5 -RELEASE FreeBSD FreeBSD 5.4 -RELENG FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.4 -PRERELEASE FreeBSD FreeBSD 5.3 -STABLE FreeBSD FreeBSD 5.3 -RELENG FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 5.3 FreeBSD FreeBSD 5.2.1 -RELEASE FreeBSD FreeBSD 5.2 -RELENG FreeBSD FreeBSD 5.2 -RELEASE FreeBSD FreeBSD 5.2 FreeBSD FreeBSD 5.1 -RELENG FreeBSD FreeBSD 5.1 -RELEASE/Alpha FreeBSD FreeBSD 5.1 -RELEASE-p5 FreeBSD FreeBSD 5.1 -RELEASE FreeBSD FreeBSD 5.1 FreeBSD FreeBSD 5.0 .x FreeBSD FreeBSD 5.0 -RELENG FreeBSD FreeBSD 5.0 -RELEASE-p14 FreeBSD FreeBSD 5.0 alpha FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 6.2 FreeBSD FreeBSD 6.1 -STABLE FreeBSD FreeBSD 6.1 -RELEASE-p10 FreeBSD FreeBSD 6.1 -RELEASE FreeBSD FreeBSD 6.0 -RELEASE-p5 FreeBSD FreeBSD 5.4-STABLE Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Apple Mac OS X Server 10.4.11 Apple Mac OS X 10.4.11 |
| Not Vulnerable: | |
Discussion
tcpdump Print-bgp.C Remote Integer Underflow Vulnerability
The 'tcpdump' utility is prone to an integer-underflow vulnerability because it fails to bounds-check user-supplied input before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary malicious code in the context of the user running the affected application. Failed exploit attempts will likely crash the affected application.
This issue affects tcpdump 3.9.6 and prior versions.
The 'tcpdump' utility is prone to an integer-underflow vulnerability because it fails to bounds-check user-supplied input before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary malicious code in the context of the user running the affected application. Failed exploit attempts will likely crash the affected application.
This issue affects tcpdump 3.9.6 and prior versions.
Exploit / POC
tcpdump Print-bgp.C Remote Integer Underflow Vulnerability
A proof of concept that demonstrates this issue is available:
A proof of concept that demonstrates this issue is available:
Solution / Fix
tcpdump Print-bgp.C Remote Integer Underflow Vulnerability
Solution:
The vendor has released a fix in the CVS head. Please see the references for more information.
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 arm
Debian Linux 4.0 powerpc
FreeBSD FreeBSD 6.2
Debian Linux 4.0 sparc
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Debian Linux 3.1 arm
Debian Linux 3.1 mips
Debian Linux 3.1 s/390
Debian Linux 3.1 ia-32
Solution:
The vendor has released a fix in the CVS head. Please see the references for more information.
Debian Linux 4.0 amd64
-
Debian tcpdump_3.9.5-2etch1_amd64.deb
http://security.debian.org/pool/updates/main/t/tcpdump/tcpdump_3.9.5-2 etch1_amd64.deb
Debian Linux 4.0 ia-32
-
Debian tcpdump_3.9.5-2etch1_i386.deb
http://security.debian.org/pool/updates/main/t/tcpdump/tcpdump_3.9.5-2 etch1_i386.deb
Debian Linux 4.0 arm
-
Debian tcpdump_3.9.5-2etch1_arm.deb
http://security.debian.org/pool/updates/main/t/tcpdump/tcpdump_3.9.5-2 etch1_arm.deb
Debian Linux 4.0 powerpc
-
Debian tcpdump_3.9.5-2etch1_powerpc.deb
http://security.debian.org/pool/updates/main/t/tcpdump/tcpdump_3.9.5-2 etch1_powerpc.deb
FreeBSD FreeBSD 6.2
-
FreeBSD tcpdump.patch
http://security.freebsd.org/patches/SA-07:06/tcpdump.patch
Debian Linux 4.0 sparc
-
Debian tcpdump_3.9.5-2etch1_sparc.deb
http://security.debian.org/pool/updates/main/t/tcpdump/tcpdump_3.9.5-2 etch1_sparc.deb
Apple Mac OS X 10.4.11
-
Apple Security Update 2007-009 (10.4.11 PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16521&cat= 1&platform=osx&method=sa/SecUpd2007-009Univ.dmg -
Apple Security Update 2007-009 (10.4.11 Universal)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16521&cat= 1&platform=osx&method=sa/SecUpd2007-009Univ.dmg
Apple Mac OS X Server 10.4.11
-
Apple Security Update 2007-009 (10.4.11 PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16521&cat= 1&platform=osx&method=sa/SecUpd2007-009Univ.dmg -
Apple Security Update 2007-009 (10.4.11 Universal)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16521&cat= 1&platform=osx&method=sa/SecUpd2007-009Univ.dmg
Debian Linux 3.1 arm
-
Debian tcpdump_3.8.3-5sarge3_arm.deb
http://security.debian.org/pool/updates/main/t/tcpdump/tcpdump_3.8.3-5 sarge3_arm.deb
Debian Linux 3.1 mips
-
Debian tcpdump_3.8.3-5sarge3_mips.deb
http://security.debian.org/pool/updates/main/t/tcpdump/tcpdump_3.8.3-5 sarge3_mips.deb
Debian Linux 3.1 s/390
-
Debian tcpdump_3.8.3-5sarge3_s390.deb
http://security.debian.org/pool/updates/main/t/tcpdump/tcpdump_3.8.3-5 sarge3_s390.deb
Debian Linux 3.1 ia-32
-
Debian tcpdump_3.8.3-5sarge3_i386.deb
http://security.debian.org/pool/updates/main/t/tcpdump/tcpdump_3.8.3-5 sarge3_i386.deb
References
tcpdump Print-bgp.C Remote Integer Underflow Vulnerability
References:
References:
- CVS log for tcpdump/print-bgp.c (tcpdump)
- tcpdump Homepage (tcpdump)
- GLSA 200707-14 / tcpdump (Gentoo Linux)
- RHSA-2007:0368-4 tcpdump security and bug fix update (Red Hat)
- RHSA-2007:0387 Moderate: tcpdump security and bug fix update (Red Hat)
- SUSE-SR:2007:016 (Novell)