CVE-2014-9140
published 2014-12-05CVE-2014-9140: Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.76%
92.2th percentile
Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | tcpdump | < tcpdump 4.6.2-3 (bookworm) | tcpdump 4.6.2-3 (bookworm) |
| redhat | tcpdump | <= 4.6.2 | — |
| tcpdump | tcpdump | >= 0 < 4.6.2-3 | 4.6.2-3 |
| tcpdump | tcpdump | >= 0 < 4.6.2-3 | 4.6.2-3 |
| tcpdump | tcpdump | >= 0 < 4.6.2-3 | 4.6.2-3 |
| tcpdump | tcpdump | >= 0 < 4.6.2-3 | 4.6.2-3 |
| tcpdump | tcpdump | >= 0 < 4.5.1-2ubuntu1.1 | 4.5.1-2ubuntu1.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
tcpdump vulnerabilities
vendor_ubuntu·2014-12-04·CVSS 5.0
CVE-2014-8767 [MEDIUM] tcpdump vulnerabilities
Title: tcpdump vulnerabilities
Summary: Several security issues were fixed in tcpdump.
Steffen Bauch discovered that tcpdump incorrectly handled printing OSLR
packets. A remote attacker could use this issue to cause tcpdump to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2014-8767)
Steffen Bauch discovered that tcpdump incorrectly handled printing GeoNet
packets. A remote attacker could use this issue to cause tcpdump to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only applied to Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2014-8768)
Steffen Bauch discovered that tcpdump incorrectly handled printing AODV
packets. A remote attacker could use this issue to cause tcpdump to crash,
resulting in a denial of service
Red Hat
tcpdump: incorrect handling of PPP packets printing
vendor_redhat·2014-11-24·CVSS 5.0
CVE-2014-9140 [MEDIUM] tcpdump: incorrect handling of PPP packets printing
tcpdump: incorrect handling of PPP packets printing
Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet.
Package: tcpdump (Red Hat Enterprise Linux 5) - Will not fix
Package: tcpdump (Red Hat Enterprise Linux 6) - Will not fix
Package: tcpdump (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-9140: tcpdump - Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and ear...
vendor_debian·2014·CVSS 5.0
CVE-2014-9140 [MEDIUM] CVE-2014-9140: tcpdump - Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and ear...
Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet.
Scope: local
bookworm: resolved (fixed in 4.6.2-3)
bullseye: resolved (fixed in 4.6.2-3)
forky: resolved (fixed in 4.6.2-3)
sid: resolved (fixed in 4.6.2-3)
trixie: resolved (fixed in 4.6.2-3)
Apple
CVE-2014-9140: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 5.0
CVE-2014-9140 [MEDIUM] CVE-2014-9140: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2014-9140
Component: CVE-2014-9140
GHSA
GHSA-v564-r5jq-5c36: Buffer overflow in the ppp_hdlc function in print-ppp
ghsa_unreviewed·2022-05-14
CVE-2014-9140 [MEDIUM] CWE-119 GHSA-v564-r5jq-5c36: Buffer overflow in the ppp_hdlc function in print-ppp
Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet.
OSV
CVE-2014-9140: Buffer overflow in the ppp_hdlc function in print-ppp
osv·2014-12-05·CVSS 5.0
CVE-2014-9140 [MEDIUM] CVE-2014-9140: Buffer overflow in the ppp_hdlc function in print-ppp
Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet.
OSV
tcpdump vulnerabilities
osv·2014-12-04·CVSS 5.0
CVE-2014-8767 [MEDIUM] tcpdump vulnerabilities
tcpdump vulnerabilities
Steffen Bauch discovered that tcpdump incorrectly handled printing OSLR
packets. A remote attacker could use this issue to cause tcpdump to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2014-8767)
Steffen Bauch discovered that tcpdump incorrectly handled printing GeoNet
packets. A remote attacker could use this issue to cause tcpdump to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only applied to Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2014-8768)
Steffen Bauch discovered that tcpdump incorrectly handled printing AODV
packets. A remote attacker could use this issue to cause tcpdump to crash,
resulting in a denial of service, reveal sensitive information, or possibly
execute arbitrary co
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9140 tcpdump: incorrect handling of PPP packets printing [fedora-all]
bugzilla·2014-12-05·CVSS 5.0
CVE-2014-9140 [MEDIUM] CVE-2014-9140 tcpdump: incorrect handling of PPP packets printing [fedora-all]
CVE-2014-9140 tcpdump: incorrect handling of PPP packets printing [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2014-9140 tcpdump: incorrect handling of PPP packets printing
bugzilla·2014-12-05·CVSS 5.0
CVE-2014-9140 [MEDIUM] CVE-2014-9140 tcpdump: incorrect handling of PPP packets printing
CVE-2014-9140 tcpdump: incorrect handling of PPP packets printing
It was discovered that tcpdump incorrectly handled the printing of PPP packets. A remote attacker could use this flaw to cause tcpdump to crash, resulting in a denial of service, or possibly execute arbitrary code.
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/0f95d441e4b5d7512cc5c326c8668a120e048eda
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1171184]
---
tcpdump-4.5.1-3.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
---
tcpdump-4.6.2-3.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
---
Analysis
http://advisories.mageia.org/MGASA-2014-0511.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00084.htmlhttp://packetstormsecurity.com/files/130730/tcpdump-Denial-Of-Service-Code-Execution.htmlhttp://seclists.org/tcpdump/2014/q4/72http://www.debian.org/security/2014/dsa-3086http://www.debian.org/security/2015/dsa-3193http://www.mandriva.com/security/advisories?name=MDVSA-2014:240http://www.mandriva.com/security/advisories?name=MDVSA-2015:125http://www.securityfocus.com/archive/1/534829/100/0/threadedhttp://www.securityfocus.com/bid/71468http://www.ubuntu.com/usn/USN-2433-1https://github.com/the-tcpdump-group/tcpdump/commit/0f95d441e4b5d7512cc5c326c8668a120e048edahttps://support.apple.com/kb/HT205031http://advisories.mageia.org/MGASA-2014-0511.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00084.htmlhttp://packetstormsecurity.com/files/130730/tcpdump-Denial-Of-Service-Code-Execution.htmlhttp://seclists.org/tcpdump/2014/q4/72http://www.debian.org/security/2014/dsa-3086http://www.debian.org/security/2015/dsa-3193http://www.mandriva.com/security/advisories?name=MDVSA-2014:240http://www.mandriva.com/security/advisories?name=MDVSA-2015:125http://www.securityfocus.com/archive/1/534829/100/0/threadedhttp://www.securityfocus.com/bid/71468http://www.ubuntu.com/usn/USN-2433-1https://github.com/the-tcpdump-group/tcpdump/commit/0f95d441e4b5d7512cc5c326c8668a120e048edahttps://support.apple.com/kb/HT205031
2014-12-05
Published