The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-libpcapalpine-linux-upgrade-tcpdump | Aug 22, 2024 | Oct 3, 2019 | |
| Debian | debian-upgrade-tcpdump | Jul 30, 2024 | Oct 3, 2019 | |
| F5 Big Ip | f5-bigip-upgrade-latest | Jun 17, 2026 | Nov 6, 2019 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Oct 3, 2019 | |
| Ubuntu | ubuntu-pro-upgrade-tcpdumpubuntu-upgrade-tcpdump | Mar 17, 2022 | Oct 3, 2019 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Oct 3, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub