← Vulnerability feed

Vulnerability record · CVE-2003-1029 · published 17 February 2004

CVE-2003-1029: Lbl tcpdump vulnerability

Lbl · Tcpdump

The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.

5.0 CVSS 2.0 Medium EPSS 9.9% · top 4.6%
5.0CVSS 2.0 base score
9.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-1029 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2000-1026Lbl tcpdump vulnerabilityMultiple buffer overflows in LBNL tcpdump allow remote attackers to execute arbitrary commands.EPSS 6.0%7.5CVE-2002-1350Lbl tcpdump vulnerabilityThe BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data, which allows remote attackers to cause a denial of service (applicat…EPSS 2.4%7.5CVE-2002-0380Lbl tcpdump vulnerabilityBuffer overflow in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via an NFS pack…EPSS 5.0%7.5CVE-1999-1024Lbl tcpdump vulnerabilityip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infin…EPSS 2.9%7.5CVE-2001-1279Lbl tcpdump vulnerabilityBuffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code…EPSS 4.8%5.0CVE-2005-1267Lbl tcpdump vulnerabilityThe bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attacke…EPSS 14%5.0CVE-2005-1278Lbl tcpdump vulnerabilityThe isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop…EPSS 11%5.0CVE-2005-1279Lbl tcpdump vulnerabilitytcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly ha…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2003-1029), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.