CVE-2003-0108
tcpdump 3.6-3.7.1 - Denial of Service via Malformed ISAKMP Packet
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-0108. PoCs published by The Salvia Twist.
AI-analyzed exploit summary This exploit crafts a malformed ISAKMP packet to trigger a denial-of-service condition in vulnerable versions of tcpdump by causing it to enter an infinite loop. It supports both spoofed and non-spoofed packet sending.
Description
isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.
Exploits (1)
This exploit crafts a malformed ISAKMP packet to trigger a denial-of-service condition in vulnerable versions of tcpdump by causing it to enter an infinite loop. It supports both spoofed and non-spoofed packet sending.