Описание
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.
A flaw was found in libpcap. The rpcap client code, which processes RPCAP_MSG_PACKET messages from a server, incorrectly validates its headers. A malicious server could exploit this vulnerability by sending a specially crafted message, causing the client to read up to 20 bytes of memory beyond its intended buffer. This out-of-bounds read could lead to the disclosure of sensitive information from the client's process memory.
Отчет
This Moderate impact information disclosure flaw in libpcap's rpcap client allows a malicious server to read up to 20 bytes of client process memory. The vulnerability occurs when the client processes a crafted RPCAP_MSG_PACKET message, leading to an out-of-bounds read. Exploitation requires the client to connect to a controlled malicious server, limiting the attack surface.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libpcap | Fix deferred | ||
| Red Hat Enterprise Linux 6 | libpcap | Fix deferred | ||
| Red Hat Enterprise Linux 7 | libpcap | Fix deferred | ||
| Red Hat Enterprise Linux 8 | libpcap | Fix deferred | ||
| Red Hat Enterprise Linux 9 | libpcap | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5 Medium
CVSS3
Связанные уязвимости
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.
The rpcap client code that processes a RPCAP_MSG_PACKET message receiv ...
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.
5 Medium
CVSS3