CVE-2015-3138
published 2017-09-28CVE-2015-3138: print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
PriorityP432high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.28%
81.2th percentile
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tcpdump | — | — |
| opensuse | leap | — | — |
| opensuse_project | leap | — | — |
| tcpdump | tcpdump | <= 4.7.3 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-75gj-485x-v865: print-wb
ghsa_unreviewed·2022-05-14
CVE-2015-3138 [HIGH] CWE-20 GHSA-75gj-485x-v865: print-wb
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
Red Hat
tcpdump: denial of service in print-wb.c
vendor_redhat·2015-03-25·CVSS 7.5
CVE-2015-3138 [HIGH] tcpdump: denial of service in print-wb.c
tcpdump: denial of service in print-wb.c
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
Statement: Not vulnerable. This issue did not affect the versions of tcpdump as shipped with Red Hat Enterprise Linux 5, 6 and 7 as they did not include vulnerable code.
Package: tcpdump (Red Hat Enterprise Linux 5) - Not affected
Package: tcpdump (Red Hat Enterprise Linux 6) - Not affected
Package: tcpdump (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2015-3138: tcpdump - print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of ...
vendor_debian·2015·CVSS 7.5
CVE-2015-3138 [HIGH] CVE-2015-3138: tcpdump - print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of ...
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7384 nodejs: unspecified DoS vulnerability
bugzilla·2015-10-05·CVSS 7.5
CVE-2015-7384 [HIGH] CVE-2015-7384 nodejs: unspecified DoS vulnerability
CVE-2015-7384 nodejs: unspecified DoS vulnerability
An unspecified vulnerability has been found in Nodej.js:
https://github.com/nodejs/node/issues/3138
This flaw is reported to affect version 4.0.0, 4.1.0, and 4.1.1 of Node.js.
Statement:
This issue did not affect the versions of Node.js as shipped in any Red Hat product.
Discussion:
External References:
https://github.com/nodejs/node/issues/3138
Bugzilla
CVE-2015-3138 tcpdump: denial of service in print-wb.c
bugzilla·2015-04-16·CVSS 7.5
CVE-2015-3138 [HIGH] CVE-2015-3138 tcpdump: denial of service in print-wb.c
CVE-2015-3138 tcpdump: denial of service in print-wb.c
Recently an independent researcher had discovered a vulnerability in tcpdump, which would be a segmentation fault triggered through feeding into tcpdump a crafted packet, either from a live network interface or from a .pcap file. It has been assigned CVE-2015-3138 and you can find the steps to reproduce it here:
https://github.com/the-tcpdump-group/tcpdump/issues/446
Subsequent analysis made it clear that the vulnerability was introduced into one of tcpdump functions by an accident not long before the 4.7.0 release. It remained in tcpdump releases 4.7.2 and 4.7.3 (4.7.1 was never released). The next release, 4.7.4, will have it fixed, but it is likely to be delayed. Since the vulnerability has been public for a few weeks, meanwhile
http://lists.opensuse.org/opensuse-updates/2017-05/msg00018.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1212342https://github.com/the-tcpdump-group/tcpdump/commit/3ed82f4ed0095768529afc22b923c8f7171fff70https://github.com/the-tcpdump-group/tcpdump/issues/446http://lists.opensuse.org/opensuse-updates/2017-05/msg00018.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1212342https://github.com/the-tcpdump-group/tcpdump/commit/3ed82f4ed0095768529afc22b923c8f7171fff70https://github.com/the-tcpdump-group/tcpdump/issues/446
2017-09-28
Published