Heap-based buffer overread in Tcpdump - CVE-2017-16808

 

Heap-based buffer overread in Tcpdump - CVE-2017-16808

Published: November 14, 2017 / Updated: October 22, 2019


Vulnerability identifier: #VU9337
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16808
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to heap-based buffer overread in 'addrtoname.c' when handling malicious input. A remote attacker can supply a specially crafted pcap fil, trigger buffer overread and cause the service to crash.

Successful exploitation of the vulnerability results in denial of service.


Affected software

Tcpdump
IBM VIOS
tcpdump (Alpine package)
tcpdump
IBM AIX
Slackware Linux
Opensuse
Fedora

How to mitigate CVE-2017-16808

Install updates from vendor's website.

Tcpdump - update to 4.9.3
tcpdump (Alpine package) - update to 4.9.3-r0
tcpdump - addressed in versions 4.9.3-1.fc29, 4.9.3-1.fc30, 4.9.3-1.fc31

External References

Related Security Bulletins