Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16228

Опубликовано: 02 окт. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().

A flaw was found in tcpdump where an uninitialized buffer is accessed in tcpdump while printing HNCP packets captured in a pcap file or coming from the network. A remote attacker may abuse this flaw by sending specially crafted packets that, when printed, would trigger the flaw and crash the application. System availability is the highest threat from this vulnerability.

Отчет

This issue does not affect the versions of tcpdump as shipped with Red Hat Enterprise Linux 7 as they already include the patch.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5tcpdumpOut of support scope
Red Hat Enterprise Linux 6tcpdumpOut of support scope
Red Hat Enterprise Linux 7tcpdumpNot affected
Red Hat Enterprise Linux 8tcpdumpFixedRHSA-2020:476004.11.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=1760514tcpdump: Access to uninitialized buffer in print_prefix() function in print-hncp.c

EPSS

Процентиль: 84%
0.02169
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().

CVSS3: 7.5
nvd
около 6 лет назад

The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().

CVSS3: 7.5
debian
около 6 лет назад

The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in prin ...

CVSS3: 7.5
github
больше 3 лет назад

The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость функции print-hncp.c:print_prefix() утилиты для перехвата и анализа сетевого трафика tcpdump, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 84%
0.02169
Низкий

7.5 High

CVSS3