CVE-2007-3798

Publication date 16 July 2007

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.

Status

Package Ubuntu Release Status
tcpdump 7.04 feisty
Fixed 3.9.5-2ubuntu1
6.10 edgy
Fixed 3.9.4-4ubuntu0.2
6.06 LTS dapper
Fixed 3.9.4-2ubuntu0.2

Severity score breakdown

Parameter Value
Base score 9.8 · Critical
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Related Ubuntu Security Notices (USN)

    • USN-492-1
    • tcpdump vulnerability
    • 31 July 2007

Other references