Heap-based buffer overread in Tcpdump - CVE-2017-16808
Published: November 14, 2017 / Updated: October 22, 2019
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to heap-based buffer overread in 'addrtoname.c' when handling malicious input. A remote attacker can supply a specially crafted pcap fil, trigger buffer overread and cause the service to crash.
Successful exploitation of the vulnerability results in denial of service.
Affected software
IBM VIOS
tcpdump (Alpine package)
tcpdump
IBM AIX
Slackware Linux
Opensuse
Fedora
How to mitigate CVE-2017-16808
tcpdump (Alpine package) - update to 4.9.3-r0
tcpdump - addressed in versions 4.9.3-1.fc29, 4.9.3-1.fc30, 4.9.3-1.fc31
External References
Related Security Bulletins
- Denial of service in Tcpdump
- OpenSUSE Linux update for tcpdump
- OpenSUSE Linux update for tcpdump
- OpenSUSE Linux update for tcpdump
- Multiple vulnerabilities in Tcpdump
- Slackware Linux update for tcpdump
- IBM AIX update for tcpdump
- Heap-based buffer overread in tcpdump (Alpine package)
- Fedora 31 update for tcpdump
- Fedora 30 update for tcpdump
- Fedora 29 update for tcpdump