Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-13011

Опубликовано: 13 сент. 2017
Источник: redhat
CVSS3: 6.5

Описание

Several protocol parsers in tcpdump before 4.9.2 could cause a buffer overflow in util-print.c:bittok2str_internal().

A vulnerability was found in tcpdump's verbose printing of packet data. A crafted pcap file or specially crafted network traffic could cause tcpdump to write out of bounds in the BSS segment, potentially causing tcpdump to display truncated or incorrectly decoded fields or crash with a segmentation violation. This does not affect tcpdump when used with the -w option to save a pcap file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5tcpdumpWill not fix
Red Hat Enterprise Linux 6tcpdumpWill not fix
Red Hat Enterprise Linux 7tcpdumpFixedRHEA-2018:070510.04.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1490578tcpdump: Buffer overflow in util-print.c:bittok2str_internal()

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

Several protocol parsers in tcpdump before 4.9.2 could cause a buffer overflow in util-print.c:bittok2str_internal().

CVSS3: 9.8
nvd
почти 9 лет назад

Several protocol parsers in tcpdump before 4.9.2 could cause a buffer overflow in util-print.c:bittok2str_internal().

CVSS3: 9.8
debian
почти 9 лет назад

Several protocol parsers in tcpdump before 4.9.2 could cause a buffer ...

CVSS3: 9.8
github
больше 4 лет назад

Several protocol parsers in tcpdump before 4.9.2 could cause a buffer overflow in util-print.c:bittok2str_internal().

suse-cvrf
почти 9 лет назад

Security update for tcpdump

6.5 Medium

CVSS3