CVE-2007-1218
published 2007-03-02CVE-2007-1218: Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.82%
85.0th percentile
Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame. NOTE: this was originally referred to as heap-based, but it might be stack-based.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tcpdump | < tcpdump 3.9.5-2 (bookworm) | tcpdump 3.9.5-2 (bookworm) |
| tcpdump | tcpdump | <= 3.9.5 | — |
| tcpdump | tcpdump | >= 0 < 3.9.5-2 | 3.9.5-2 |
| tcpdump | tcpdump | >= 0 < 3.9.5-2 | 3.9.5-2 |
| tcpdump | tcpdump | >= 0 < 3.9.5-2 | 3.9.5-2 |
| tcpdump | tcpdump | >= 0 < 3.9.5-2 | 3.9.5-2 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
tcpdump vulnerability
vendor_ubuntu·2007-03-06
CVE-2007-1218 tcpdump vulnerability
Title: tcpdump vulnerability
Summary: tcpdump vulnerability
Moritz Jodeit discovered that tcpdump had an overflow in the 802.11
packet parser. Remote attackers could send specially crafted packets,
crashing tcpdump, possibly leading to a denial of service.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
tcpdump denial of service
vendor_redhat·2007-03-01·CVSS 6.8
CVE-2007-1218 [MEDIUM] tcpdump denial of service
tcpdump denial of service
Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame. NOTE: this was originally referred to as heap-based, but it might be stack-based.
Statement: Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=232347
The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: https://access.redhat.com/security/updates/classification/
Debian
CVE-2007-1218: tcpdump - Off-by-one buffer overflow in the parse_elements function in the 802.11 printer ...
vendor_debian·2007·CVSS 6.8
CVE-2007-1218 [MEDIUM] CVE-2007-1218: tcpdump - Off-by-one buffer overflow in the parse_elements function in the 802.11 printer ...
Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame. NOTE: this was originally referred to as heap-based, but it might be stack-based.
Scope: local
bookworm: resolved (fixed in 3.9.5-2)
bullseye: resolved (fixed in 3.9.5-2)
forky: resolved (fixed in 3.9.5-2)
sid: resolved (fixed in 3.9.5-2)
trixie: resolved (fixed in 3.9.5-2)
GHSA
GHSA-r3xv-hqxp-h6pv: Off-by-one buffer overflow in the parse_elements function in the 802
ghsa_unreviewed·2022-05-01
CVE-2007-1218 [MEDIUM] CWE-119 GHSA-r3xv-hqxp-h6pv: Off-by-one buffer overflow in the parse_elements function in the 802
Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame. NOTE: this was originally referred to as heap-based, but it might be stack-based.
OSV
CVE-2007-1218: Off-by-one buffer overflow in the parse_elements function in the 802
osv·2007-03-02·CVSS 6.8
CVE-2007-1218 [MEDIUM] CVE-2007-1218: Off-by-one buffer overflow in the parse_elements function in the 802
Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame. NOTE: this was originally referred to as heap-based, but it might be stack-based.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-1218 tcpdump denial of service
bugzilla·2007-03-15·CVSS 6.8
CVE-2007-1218 [MEDIUM] CVE-2007-1218 tcpdump denial of service
CVE-2007-1218 tcpdump denial of service
+++ This bug was initially created as a clone of Bug #232347 +++
A potential denial of service flaw due to a single byte overflow was found in
the way tcpdump processes 802.11 packets:
http://seclists.org/fulldisclosure/2007/Mar/0003.html
The upstream patch is here:
http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c?r1=1.42&r2=1.43
From inspecting our packages it seems that the initial, incorrect test isn't
even present, which still leaves our packages vulnerable to this flaw.
-- Additional comment from [email protected] on 2007-03-14 17:12 EST --
This flaw also affects RHEL 3 and RHEL4. The code in question is not present in
RHEL 2.1
Discussion:
Can we get this into 4.6?
Cheers!
Fábio
---
This request was evaluated by Red Hat P
Bugzilla
CVE-2007-1218 tcpdump denial of service
bugzilla·2007-03-15·CVSS 6.8
CVE-2007-1218 [MEDIUM] CVE-2007-1218 tcpdump denial of service
CVE-2007-1218 tcpdump denial of service
+++ This bug was initially created as a clone of Bug #232347 +++
A potential denial of service flaw due to a single byte overflow was found in
the way tcpdump processes 802.11 packets:
http://seclists.org/fulldisclosure/2007/Mar/0003.html
The upstream patch is here:
http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c?r1=1.42&r2=1.43
From inspecting our packages it seems that the initial, incorrect test isn't
even present, which still leaves our packages vulnerable to this flaw.
-- Additional comment from [email protected] on 2007-03-14 17:12 EST --
This flaw also affects RHEL 3 and RHEL4. The code in question is not present in
RHEL 2.1
Discussion:
Can we get this into 3.9?
---
Closing after years of inactivity.
Bugzilla
CVE-2007-1218 tcpdump denial of service
bugzilla·2007-03-14·CVSS 6.8
CVE-2007-1218 [MEDIUM] CVE-2007-1218 tcpdump denial of service
CVE-2007-1218 tcpdump denial of service
A potential denial of service flaw due to a single byte overflow was found in
the way tcpdump processes 802.11 packets:
http://seclists.org/fulldisclosure/2007/Mar/0003.html
The upstream patch is here:
http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c?r1=1.42&r2=1.43
From inspecting our packages it seems that the initial, incorrect test isn't
even present, which still leaves our packages vulnerable to this flaw.
Discussion:
This flaw also affects RHEL 3 and RHEL4. The code in question is not present in
RHEL 2.1
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the upda
Bugzilla
CVE-2007-1218 tcpdump denial of service
bugzilla·2007-03-14·CVSS 6.8
CVE-2007-1218 [MEDIUM] CVE-2007-1218 tcpdump denial of service
CVE-2007-1218 tcpdump denial of service
+++ This bug was initially created as a clone of Bug #232347 +++
A potential denial of service flaw due to a single byte overflow was found in
the way tcpdump processes 802.11 packets:
http://seclists.org/fulldisclosure/2007/Mar/0003.html
The upstream patch is here:
http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c?r1=1.42&r2=1.43
From inspecting our packages it seems that the initial, incorrect test isn't
even present, which still leaves our packages vulnerable to this flaw.
Discussion:
This flaw should also affect FC5 and the upcoming FC7
---
Fixed in
tcpdump-3.9.4-4.fc5
tcpdump-3.9.4-10.fc6
tcpdump-3.9.5-3.fc7
http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.chttp://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c?r1=1.31.2.11&r2=1.31.2.12http://docs.info.apple.com/article.html?artnum=307179http://fedoranews.org/cms/node/2798http://fedoranews.org/cms/node/2799http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.htmlhttp://seclists.org/fulldisclosure/2007/Mar/0003.htmlhttp://secunia.com/advisories/24318http://secunia.com/advisories/24354http://secunia.com/advisories/24423http://secunia.com/advisories/24451http://secunia.com/advisories/24583http://secunia.com/advisories/24610http://secunia.com/advisories/27580http://secunia.com/advisories/28136http://www.debian.org/security/2007/dsa-1272http://www.mandriva.com/security/advisories?name=MDKSA-2007:056http://www.mandriva.com/security/advisories?name=MDKSA-2007:155http://www.osvdb.org/32427http://www.redhat.com/support/errata/RHSA-2007-0368.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0387.htmlhttp://www.securityfocus.com/bid/22772http://www.securitytracker.com/id?1017717http://www.turbolinux.com/security/2007/TLSA-2007-46.txthttp://www.ubuntu.com/usn/usn-429-1http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlhttp://www.vupen.com/english/advisories/2007/0793http://www.vupen.com/english/advisories/2007/4238https://bugs.gentoo.org/show_bug.cgi?id=168916https://exchange.xforce.ibmcloud.com/vulnerabilities/32749https://issues.rpath.com/browse/RPL-1100https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9520http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.chttp://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c?r1=1.31.2.11&r2=1.31.2.12http://docs.info.apple.com/article.html?artnum=307179http://fedoranews.org/cms/node/2798http://fedoranews.org/cms/node/2799http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.htmlhttp://seclists.org/fulldisclosure/2007/Mar/0003.htmlhttp://secunia.com/advisories/24318http://secunia.com/advisories/24354http://secunia.com/advisories/24423http://secunia.com/advisories/24451http://secunia.com/advisories/24583http://secunia.com/advisories/24610http://secunia.com/advisories/27580http://secunia.com/advisories/28136http://www.debian.org/security/2007/dsa-1272http://www.mandriva.com/security/advisories?name=MDKSA-2007:056http://www.mandriva.com/security/advisories?name=MDKSA-2007:155http://www.osvdb.org/32427http://www.redhat.com/support/errata/RHSA-2007-0368.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0387.htmlhttp://www.securityfocus.com/bid/22772http://www.securitytracker.com/id?1017717http://www.turbolinux.com/security/2007/TLSA-2007-46.txthttp://www.ubuntu.com/usn/usn-429-1http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlhttp://www.vupen.com/english/advisories/2007/0793http://www.vupen.com/english/advisories/2007/4238https://bugs.gentoo.org/show_bug.cgi?id=168916https://exchange.xforce.ibmcloud.com/vulnerabilities/32749https://issues.rpath.com/browse/RPL-1100https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9520
2007-03-02
Published