CVE-2004-0184

Tcpdump < 3.8.1 - Integer Underflow

Title source: rule

Description

Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Rapid7 · cremotelinux
https://www.exploit-db.com/exploits/171

Scores

EPSS 0.6531
EPSS Percentile 98.5%

Classification

CWE
CWE-125 CWE-191
Status draft

Affected Products (1)

tcpdump/tcpdump < 3.8.1

Timeline

Published May 04, 2004
Tracked Since Feb 18, 2026