tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | Jul 22, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade tcpdump | Nov 19, 2019 | Jul 22, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade tcpdump | Nov 28, 2019 | Jul 22, 2019 |
| Oracle Solaris | — | Upgrade diagnostic/tcpdump to version 4.9.2-11.4.13.0.1.2.0 on Solaris 11.4 | Sep 17, 2019 | Jul 22, 2019 |
| Suse | — | Upgrade tcpdump | Aug 8, 2019 | Jul 22, 2019 |
| Ubuntu | — | Upgrade tcpdump (Ubuntu Pro)Upgrade tcpdump | Jan 28, 2020 | Jul 22, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 22, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub