CVE-2002-1350 describes a denial-of-service vulnerability in tcpdump versions 3.6.x prior to 3.7, specifically within its BGP decoding routines. This flaw allows remote attackers to crash the application due to improper data copying. With a CVSS score of 7.5, it is considered highly severe, requiring no authentication and having low attack complexity, potentially leading to a complete loss of availability. While there is no known active exploitation or publicly available exploit code, the vulnerability has garnered significant community discussion, with 10 mentions across various platforms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.6.2.2.2CPE matchmatch criteria | cpe:2.3:a:lbl:tcpdump:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.