← Vulnerability feed

Vulnerability record · CVE-2004-0057 · published 17 February 2004

CVE-2004-0057: Lbl tcpdump vulnerability

Lbl · Tcpdump

The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.

5.0 CVSS 2.0 Medium EPSS 5.3% · top 7.7%
5.0CVSS 2.0 base score
5.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
68References
16 Jun 2026Last modified by NVD

Description

The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt
ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html
http://lwn.net/Alerts/66445/
http://lwn.net/Alerts/66805/
http://marc.info/?l=bugtraq&m=107577418225627&w=2
http://marc.info/?l=tcpdump-workers&m=107325073018070&w=2
http://secunia.com/advisories/10636
http://secunia.com/advisories/10639
http://secunia.com/advisories/10644
http://secunia.com/advisories/10652
http://secunia.com/advisories/10668
http://secunia.com/advisories/10718
http://secunia.com/advisories/11022
http://secunia.com/advisories/11032/
http://secunia.com/advisories/12179/
http://www.debian.org/security/2004/dsa-425 PatchVendor Advisory
http://www.kb.cert.org/vuls/id/174086 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2004:008
http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html
http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html
http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html
http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html
http://www.redhat.com/support/errata/RHSA-2004-007.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2004-008.html
http://www.securityfocus.com/archive/1/350238/30/21640/threaded
http://www.securityfocus.com/bid/9423 PatchVendor Advisory
http://www.securitytracker.com/id?1008716
https://exchange.xforce.ibmcloud.com/vulnerabilities/14837
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11197
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A851
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A854
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt
ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html
http://lwn.net/Alerts/66445/

Track CVE-2004-0057 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2000-1026Lbl tcpdump vulnerabilityMultiple buffer overflows in LBNL tcpdump allow remote attackers to execute arbitrary commands.EPSS 6.0%7.5CVE-2002-1350Lbl tcpdump vulnerabilityThe BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data, which allows remote attackers to cause a denial of service (applicat…EPSS 2.4%7.5CVE-2002-0380Lbl tcpdump vulnerabilityBuffer overflow in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via an NFS pack…EPSS 5.0%7.5CVE-1999-1024Lbl tcpdump vulnerabilityip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infin…EPSS 2.9%7.5CVE-2001-1279Lbl tcpdump vulnerabilityBuffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code…EPSS 4.8%5.0CVE-2005-1267Lbl tcpdump vulnerabilityThe bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attacke…EPSS 14%5.0CVE-2005-1278Lbl tcpdump vulnerabilityThe isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop…EPSS 11%5.0CVE-2005-1279Lbl tcpdump vulnerabilitytcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly ha…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2004-0057), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.