The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libpcapUpgrade tcpdump | Aug 22, 2024 | Oct 3, 2019 |
| Apple Osx Tcpdump | — | — | Dec 11, 2019 | Oct 3, 2019 |
| Debian | — | Upgrade tcpdump | Jul 30, 2024 | Oct 3, 2019 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 6, 2019 |
| Huawei Euleros 2_0_sp8 | — | — | Nov 28, 2019 | Oct 3, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 3, 2019 |
| Suse | — | — | Oct 16, 2019 | Oct 3, 2019 |
| Ubuntu | — | Upgrade tcpdumpUpgrade tcpdump (Ubuntu Pro) | Mar 17, 2022 | Oct 3, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 3, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub