Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h8wh-rj39-x373

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

libpcap before 1.9.1, as used in tcpdump before 4.9.3, has a buffer overflow and/or over-read because of errors in pcapng reading.

libpcap before 1.9.1, as used in tcpdump before 4.9.3, has a buffer overflow and/or over-read because of errors in pcapng reading.

EPSS

Процентиль: 20%
0.00063
Низкий

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 6 лет назад

The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.

CVSS3: 5.3
redhat
почти 6 лет назад

The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.

CVSS3: 7.8
nvd
почти 6 лет назад

The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.

CVSS3: 7.8
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.8
debian
почти 6 лет назад

The command-line argument parser in tcpdump before 4.99.0 has a buffer ...

EPSS

Процентиль: 20%
0.00063
Низкий

Дефекты

CWE-120