Zebedee: Denial of Service vulnerability A bug in Zebedee allows a remote attacker to perform a Denial of Service attack. zebedee 2005-09-20 2006-05-22 105115 remote 2.4.1-r1 2.5.3 2.5.3

Zebedee is an application that establishes an encrypted, compressed tunnel for TCP/IP or UDP data transfer between two systems.

"Shiraishi.M" reported that Zebedee crashes when "0" is received as the port number in the protocol option header.

By performing malformed requests a remote attacker could cause Zebedee to crash.

There is no known workaround at this time.

All Zebedee users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose net-misc/zebedee
BugTraq ID 14796 CVE-2005-2904 koon koon adir