Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TCPDump ISAKMP删除负载远程缓冲区溢出漏洞
Vulnerability Description
Tcpdump是一款监视网络通信和协议分析工具。 Tcpdump的ISAKMP包显示函数中存在问题,远程攻击者可以利用这个漏洞进行拒绝服务攻击或以进程权限执行任意指令。 tcpdump的ISAKMP包显示函数在处理显示ISAKMP删除负载时存在问题,由于TCPDUMP没有验证snap缓冲区中的(NSPIS * SPISIZE) fits,在尝试读取Snap缓冲区之外的数据时导致拒绝服务,或可能进程权限执行任意指令。目前没有详细漏洞细节提供。
CVSS Information
N/A
Vulnerability Type
N/A