Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-16301

Опубликовано: 03 окт. 2019
Источник: nvd
CVSS3: 7.8
CVSS2: 4.4
EPSS Низкий

Описание

The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tcpdump:tcpdump:*:*:*:*:*:*:*:*
Версия до 4.99.0 (исключая)

EPSS

Процентиль: 20%
0.00063
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-190
CWE-120

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 6 лет назад

The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.

CVSS3: 5.3
redhat
почти 6 лет назад

The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.

CVSS3: 7.8
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.8
debian
почти 6 лет назад

The command-line argument parser in tcpdump before 4.99.0 has a buffer ...

suse-cvrf
больше 3 лет назад

Security update for tcpdump

EPSS

Процентиль: 20%
0.00063
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-190
CWE-120