Allocation of Resources Without Limits or Throttling in Tcpdump - CVE-2020-8037

 

Allocation of Resources Without Limits or Throttling in Tcpdump - CVE-2020-8037

Published: November 4, 2020 / Updated: April 27, 2021


Vulnerability identifier: #VU48587
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8037
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.


Affected software

Tcpdump
cflinuxfs3
F5OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
macOS
Ubuntu
openEuler
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
Juniper Cloud Native Router
tcpdump (Alpine package)
tcpdump (Ubuntu package)
tcpdump (Red Hat package)
tcpdump
tcpdump-help
tcpdump-debuginfo
tcpdump-debugsource
BIG-IP
Junos cRPD

How to mitigate CVE-2020-8037

Install update from vendor's website.

cflinuxfs3 - update to 0.283.0
F5OS - update to 1.8.0
Isolation Segment - addressed in versions 2.7.44, 2.10.24, 2.11.13, 2.12.7
VMware Tanzu Application Service for VMs - addressed in versions 2.7.49, 2.10.31, 2.11.19, 2.12.12
macOS - addressed in versions 10.14.6 18G9028, 10.15.7 19H1030, 11.3 20E232
tcpdump (Ubuntu package) - addressed in versions 4.9.3-0ubuntu0.18.04.2, 4.9.3-4ubuntu0.1, 4.9.30ubuntu0.16.04.1+esm1
tcpdump (Red Hat package) - update to 4.9.3-2.el8
tcpdump - addressed in versions 4.9.3-4.fc32, 4.9.3-5.fc33
tcpdump - update to 4.9.3-5
tcpdump-help - update to 4.9.3-5
tcpdump-debuginfo - update to 4.9.3-5
tcpdump-debugsource - update to 4.9.3-5
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins