CVE-2004-0183
Estado: ModificadaMedia (5)—
TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.62%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-125
Referencias
- http://marc.info/?l=bugtraq&m=108067265931525&w=2
- http://secunia.com/advisories/11258
- http://secunia.com/advisories/11320
- http://securitytracker.com/id?1009593
- http://www.debian.org/security/2004/dsa-478
- http://www.kb.cert.org/vuls/id/240790
- http://www.rapid7.com/advisories/R7-0017.html
- http://www.redhat.com/support/errata/RHSA-2004-219.html
- http://www.securityfocus.com/bid/10003
- http://www.tcpdump.org/tcpdump-changes.txt
- http://www.trustix.org/errata/2004/0015
- https://bugzilla.fedora.us/show_bug.cgi?id=1468
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15680
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A972
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9971
- http://marc.info/?l=bugtraq&m=108067265931525&w=2
- http://secunia.com/advisories/11258
- http://secunia.com/advisories/11320
- http://securitytracker.com/id?1009593
- http://www.debian.org/security/2004/dsa-478
- http://www.kb.cert.org/vuls/id/240790
- http://www.rapid7.com/advisories/R7-0017.html
- http://www.redhat.com/support/errata/RHSA-2004-219.html
- http://www.securityfocus.com/bid/10003
- http://www.tcpdump.org/tcpdump-changes.txt
- http://www.trustix.org/errata/2004/0015
- https://bugzilla.fedora.us/show_bug.cgi?id=1468
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15680
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A972
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9971
JSON original (NVD)
Mostrar
{
"id": "CVE-2004-0183",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2004-05-04T04:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=108067265931525&w=2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/11258",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/11320",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1009593",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2004/dsa-478",
"tags": [
"Broken Link",
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/240790",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.rapid7.com/advisories/R7-0017.html",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2004-219.html",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/10003",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.tcpdump.org/tcpdump-changes.txt",
"tags": [
"Release Notes"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.trustix.org/errata/2004/0015",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.fedora.us/show_bug.cgi?id=1468",
"tags": [
"Broken Link",
"Issue Tracking"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/15680",
"tags": [
"Broken Link",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A972",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9971",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=108067265931525&w=2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/11258",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/11320",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1009593",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2004/dsa-478",
"tags": [
"Broken Link",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/240790",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.rapid7.com/advisories/R7-0017.html",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2004-219.html",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/10003",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.tcpdump.org/tcpdump-changes.txt",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.trustix.org/errata/2004/0015",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.fedora.us/show_bug.cgi?id=1468",
"tags": [
"Broken Link",
"Issue Tracking"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/15680",
"tags": [
"Broken Link",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A972",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9971",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite."
},
{
"lang": "es",
"value": "TCPDUMP 3.8.1 y anteriores permite a atacantes remotos causar una denegación de servicio (caída) mediante paquetes ISAKMP conteniendo un carga útil de Dorrado con un gran númeo de SPIs, lo que causa una lectura fuera de límites, como se ha demostrado por el paquete de pruebas de protocolo ISAKMP Striker."
}
],
"lastModified": "2026-06-16T22:05:07.283",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tcpdump:tcpdump:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "770A6EDA-10B7-4DB1-B150-A40F015FE3FB",
"versionEndIncluding": "3.8.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}