Out-of-bounds read in Tcpdump - CVE-2017-11108

 

Out-of-bounds read in Tcpdump - CVE-2017-11108

Published: July 24, 2017 / Updated: July 26, 2017


Vulnerability identifier: #VU7591
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11108
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists to a boundary error in the EXTRACT_16BITS() function, called from the stp_print function for the Spanning Tree Protocol in tcpdump 4.9.0. A remote attacker can send a specially crafted network packet, trigger heap-based buffer over-read and crash the affected application.

Successful exploitation of the vulnerability may allow an attacker to perform a denial of service (DoS) attack.

Affected software

Tcpdump
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Ubuntu
tcpdump (Alpine package)
tcpdump (Red Hat package)

How to mitigate CVE-2017-11108

Update to version 4.9.1.

tcpdump (Alpine package) - update to 4.9.1-r0
tcpdump (Red Hat package) - update to 4.9.2-3.el7

External References

Related Security Bulletins