Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8037

Опубликовано: 20 апр. 2020
Источник: redhat
CVSS3: 7.5

Описание

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.

A flaw was found in tcpdump while printing PPP packets captured in a pcap file or coming from the network. This flaw allows a remote attacker to send specially crafted packets that, when printed, can lead the application to allocate a large amount of memory, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5tcpdumpOut of support scope
Red Hat Enterprise Linux 6tcpdumpOut of support scope
Red Hat Enterprise Linux 7tcpdumpOut of support scope
Red Hat Enterprise Linux 8tcpdumpFixedRHSA-2021:423609.11.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1895080tcpdump: ppp decapsulator can be convinced to allocate a large amount of memory

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.

CVSS3: 7.5
nvd
около 5 лет назад

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.

CVSS3: 7.5
msrc
около 5 лет назад

ppp decapsulator can be convinced to allocate a large amount of memory

CVSS3: 7.5
debian
около 5 лет назад

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a l ...

suse-cvrf
около 5 лет назад

Security update for tcpdump

7.5 High

CVSS3