📄 4141.txt
字号:
Rule:--Sid:4141--Summary:This event is generated when an attempt is made to exploit a knownvulnerability in tcpdump.--Impact:Serious. A Denial of Service (DoS) to tcpdump.--Detailed Information:A vulnerability exists in the way that tcpdump processes LabelDistribution Protocol (LDP) packets. A malformed LDP packet will causetcpdump to enter a DoS condition when it tries to process theinformation.--Affected Systems: tcpdump 3.8.3 and prior--Attack Scenarios:An attacker would need to construct a malformed LDP packet and transmitacross a network segment that is being monitored using tcpdump.--Ease of Attack:Simple.--False Positives:None known.--False Negatives:None known.--Corrective Action:Upgrade to the most current non-affected version of the product.LDP can be used in conjunction with md5 signatures to verify the sourceof the LDP conversation. If this option is used, it would be much moredifficult for an attacker to exploit this condition.--Contributors:Sourcefire Vulnerability Research TeamNigel Houghton <nigel.houghton@sourcefire.com>--Additional References--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -