Out-of-bounds read in Tcpdump - CVE-2017-11108
Published: July 24, 2017 / Updated: July 26, 2017
Vulnerability identifier: #VU7591
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11108
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists to a boundary error in the EXTRACT_16BITS() function, called from the stp_print function for the Spanning Tree Protocol in tcpdump 4.9.0. A remote attacker can send a specially crafted network packet, trigger heap-based buffer over-read and crash the affected application.
Successful exploitation of the vulnerability may allow an attacker to perform a denial of service (DoS) attack.
The vulnerability exists to a boundary error in the EXTRACT_16BITS() function, called from the stp_print function for the Spanning Tree Protocol in tcpdump 4.9.0. A remote attacker can send a specially crafted network packet, trigger heap-based buffer over-read and crash the affected application.
Successful exploitation of the vulnerability may allow an attacker to perform a denial of service (DoS) attack.
Affected software
Tcpdump
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Ubuntu
tcpdump (Alpine package)
tcpdump (Red Hat package)
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Ubuntu
tcpdump (Alpine package)
tcpdump (Red Hat package)
How to mitigate CVE-2017-11108
Update to version 4.9.1.
tcpdump (Alpine package) - update to 4.9.1-r0
tcpdump (Red Hat package) - update to 4.9.2-3.el7
tcpdump (Red Hat package) - update to 4.9.2-3.el7