tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet.
Software | From | Fixed in |
---|---|---|
lbl / tcpdump | 3.4 | 3.4.x |
lbl / tcpdump | 3.5a | 3.5a.x |
ethereal_group / ethereal | 0.8.4 | 0.8.4.x |
ethereal_group / ethereal | 0.8.5 | 0.8.5.x |
ethereal_group / ethereal | 0.8.6 | 0.8.6.x |