Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-2397

Опубликовано: 12 апр. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Due to a bug in packet data buffers management, the PPP printer in tcpdump can enter an infinite loop when reading a crafted DLT_PPP_SERIAL .pcap savefile. This problem does not affect any tcpdump release, but it affected the git master branch from 2023-06-05 to 2024-03-21.

A flaw was found in tcpdump. Trying to print content from a maliciously crafted .pcap file may lead to an infinite loop, resulting in a denial of service. This issue is considered low severity; for a successful attack to happen, a user must open a crafted file, and it will only crash a single user's execution of tcpdump.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libpcapNot affected
Red Hat Enterprise Linux 10tcpdumpNot affected
Red Hat Enterprise Linux 6libpcapOut of support scope
Red Hat Enterprise Linux 6tcpdumpOut of support scope
Red Hat Enterprise Linux 7libpcapOut of support scope
Red Hat Enterprise Linux 7tcpdumpOut of support scope
Red Hat Enterprise Linux 8libpcapNot affected
Red Hat Enterprise Linux 8tcpdumpFix deferred
Red Hat Enterprise Linux 9libpcapNot affected
Red Hat Enterprise Linux 9tcpdumpFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2274792tcpdump: Crafted .pcap file may lead to Denial of Service

EPSS

Процентиль: 5%
0.00023
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
почти 2 года назад

Due to a bug in packet data buffers management, the PPP printer in tcpdump can enter an infinite loop when reading a crafted DLT_PPP_SERIAL .pcap savefile. This problem does not affect any tcpdump release, but it affected the git master branch from 2023-06-05 to 2024-03-21.

CVSS3: 6.2
nvd
почти 2 года назад

Due to a bug in packet data buffers management, the PPP printer in tcpdump can enter an infinite loop when reading a crafted DLT_PPP_SERIAL .pcap savefile. This problem does not affect any tcpdump release, but it affected the git master branch from 2023-06-05 to 2024-03-21.

CVSS3: 6.2
debian
почти 2 года назад

Due to a bug in packet data buffers management, the PPP printer in tcp ...

CVSS3: 6.2
github
почти 2 года назад

Due to a bug in packet data buffers management, the PPP printer in tcpdump can enter an infinite loop when reading a crafted DLT_PPP_SERIAL .pcap savefile. This problem does not affect any tcpdump release, but it affected the git master branch from 2023-06-05 to 2024-03-21.

EPSS

Процентиль: 5%
0.00023
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2024-2397