ID:1272 - Exploit for Out-of-bounds write in Tcpdump - CVE-2015-2153

 
Main Vulnerability Database Exploits ID:1272 - Exploit for Out-of-bounds write in Tcpdump - CVE-2015-2153

ID:1272 - Exploit for Out-of-bounds write in Tcpdump - CVE-2015-2153

Published: March 18, 2020


Vulnerability identifier: #VU7688
Vulnerability risk: High
CVE-ID: CVE-2015-2153
CWE-ID: CWE-787
Exploitation vector: Remote access
Vulnerable software:
Tcpdump

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code.

The weakness exists due to an error in the rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer. A remote attacker can supply a specially crafted header length in an RPKI-RTR Protocol Data Unit (PDU), trigger out-of-bounds read or write and cause the system crash or execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Remediation

Update to version 4.7.2 or later.