tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade tcpdump | Sep 20, 2017 | Jul 8, 2017 |
| Apple Osx Tcpdump | — | Upgrade macOS to the latest versionApply OS X security update 2017-001 Sierra | Nov 1, 2017 | Jul 8, 2017 |
| Debian | — | Upgrade tcpdump | Sep 13, 2017 | Jul 8, 2017 |
| Gentoo Linux | — | Upgrade net-analyzer/tcpdump. | Oct 30, 2017 | Jul 8, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade tcpdump | Dec 4, 2019 | Jul 8, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade tcpdump | Dec 18, 2019 | Jul 8, 2017 |
| Oracle Solaris | — | Upgrade diagnostic/tcpdump to version 4.9.2-0.175.3.26.0.3.0 on Solaris 11.3 | Aug 21, 2017 | Jul 8, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 7, 2017 |
| Suse | — | Upgrade tcpdump | Oct 10, 2017 | Jul 8, 2017 |
| Ubuntu | — | Upgrade tcpdump | Sep 14, 2017 | Jul 8, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 8, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub