CVE-2004-0184 describes an integer underflow vulnerability in TCPDUMP versions 3.8.1 and earlier. This flaw, specifically within the isakmp_id_print function, can be triggered by remote attackers sending a specially crafted ISAKMP packet. The vulnerability allows for a denial of service (crash) due to an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite. The vulnerability has a CVSS score of 5.0, indicating a medium severity. It is easily exploitable over the network (AV:N/AC:L) without authentication (Au:N), leading to a partial impact on availability (A:P). While not listed on the KEV catalog, an exploit (EDB-171) is publicly available, and its FAUCET Risk Score is high at 98/100. Despite the public exploit, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.8.1CPE matchmatch criteria | cpe:2.3:a:tcpdump:tcpdump:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.