CVE-2016-7975
published 2017-01-28CVE-2016-7975: The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().
PriorityP346critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.38%
87.4th percentile
The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_sierra_10.12.4_security_update_2017-001_el_capitan_and_security_update_201 | — | — |
| debian | tcpdump | < tcpdump 4.9.0-1 (bookworm) | tcpdump 4.9.0-1 (bookworm) |
| tcpdump | tcpdump | <= 4.8.1 | — |
| tcpdump | tcpdump | >= 0 < 4.9.0-1 | 4.9.0-1 |
| tcpdump | tcpdump | >= 0 < 4.9.0-1 | 4.9.0-1 |
| tcpdump | tcpdump | >= 0 < 4.9.0-1 | 4.9.0-1 |
| tcpdump | tcpdump | >= 0 < 4.9.0-1 | 4.9.0-1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7hxg-7p97-9q82: The TCP parser in tcpdump before 4
ghsa_unreviewed·2022-05-14
CVE-2016-7975 [CRITICAL] CWE-119 GHSA-7hxg-7p97-9q82: The TCP parser in tcpdump before 4
The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().
OSV
CVE-2016-7975: The TCP parser in tcpdump before 4
osv·2017-01-28·CVSS 9.8
CVE-2016-7975 [CRITICAL] CVE-2016-7975: The TCP parser in tcpdump before 4
The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().
Apple
CVE-2016-7975: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
vendor_apple·2017-03-27·CVSS 9.8
CVE-2016-7975 [CRITICAL] CVE-2016-7975: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
Apple Security Update: About the security content of macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
Product: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
CVE: CVE-2016-7975
Component: CVE-2016-7975
Ubuntu
tcpdump vulnerabilities
vendor_ubuntu·2017-02-21
CVE-2016-7922 tcpdump vulnerabilities
Title: tcpdump vulnerabilities
Summary: tcpdump could be made to crash or run programs if it received specially
crafted network traffic.
It was discovered that tcpdump incorrectly handled certain packets. A
remote attacker could use this issue to cause tcpdump to crash, resulting
in a denial of service, or possibly execute arbitrary code.
In the default installation, attackers would be isolated by the tcpdump
AppArmor profile.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Red Hat
tcpdump: multiple overflow issues in protocol decoding
vendor_redhat·2017-02-02·CVSS 9.8
CVE-2016-7975 [CRITICAL] CWE-125 tcpdump: multiple overflow issues in protocol decoding
tcpdump: multiple overflow issues in protocol decoding
The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().
Multiple out of bounds read and integer overflow vulnerabilities were found in tcpdump affecting the decoding of various protocols. An attacker could create a crafted pcap file or send specially crafted packets to the network segment where tcpdump is running in live capture mode (without -w) which could cause it to display incorrect data, crash or enter an infinite loop.
Statement: Red Hat Product Security has rated these issues as having Moderate security impact. These issues may be fixed in a future minor release of Red Hat Enterprise Linux 7. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/sec
Debian
CVE-2016-7975: tcpdump - The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_...
vendor_debian·2016·CVSS 9.8
CVE-2016-7975 [CRITICAL] CVE-2016-7975: tcpdump - The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_...
The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().
Scope: local
bookworm: resolved (fixed in 4.9.0-1)
bullseye: resolved (fixed in 4.9.0-1)
forky: resolved (fixed in 4.9.0-1)
sid: resolved (fixed in 4.9.0-1)
trixie: resolved (fixed in 4.9.0-1)
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016
vendor_cisco
CVE-2015-7975 Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016
CVE-2015-7975: Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server. On January 19, 2016, NTP Consortium at Network Time Foundation released a security advisory detailing 12 issues regarding multiple DoS vulnerabilities, information disclosure vulnerabilities, and logic issues that may allow an attacker to shift a client's time. The vulnerabilities covered in this document are as follows: CVE-
No detection rules found.
No public exploits indexed.
Bugzilla
tcpdump: multiple overflow issues in protocol decoding
bugzilla·2017-02-03·CVSS 9.8
[CRITICAL] tcpdump: multiple overflow issues in protocol decoding
tcpdump: multiple overflow issues in protocol decoding
Multiple buffer overflows, and one integer overflow, in protocol decoding were found that may cause incorrect decoding, segmentation fault or (in the case of integer overflow) an infinite loop. These issues can be be exploited either locally, by making the target user decode a crafted .pcap file using tcpdump, or remotely by sending crafted packets to the network segment where the target system is running tcpdump decoding the live packet capture. Ability to send crafted packets to the target network segment is limited by the protocols' ability to cross network segments, or presence of firewall rules.
Upstream changelog:
http://www.tcpdump.org/tcpdump-changes.txt
Discussion:
Acknowledgments:
Name: the Tcpdump project
---
Created
Bugzilla
tcpdump: various flaws [fedora-all]
bugzilla·2017-02-03·CVSS 9.8
[CRITICAL] tcpdump: various flaws [fedora-all]
tcpdump: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one tracking bug has be
Bugzilla
CVE-2015-7975 ntp: nextvar() missing length check in ntpq
bugzilla·2016-01-20·CVSS 6.2
CVE-2015-7975 [MEDIUM] CVE-2015-7975 ntp: nextvar() missing length check in ntpq
CVE-2015-7975 ntp: nextvar() missing length check in ntpq
It was found that ntpq did not implement a proper lenght check when calling nextvar(), which executes a memcpy(), on the name buffer.
A remote attacker could potentially use this flaw to crash an ntpq client instance.
Upstream patch:
https://github.com/ntp-project/ntp/commit/12f1323d18c8d74eb14fb5ac5574183d779794c5
Discussion:
External References:
http://support.ntp.org/bin/view/Main/SecurityNotice#January_2016_NTP_4_2_8p6_Securit
http://www.talosintel.com/reports/TALOS-2016-0072/
---
Created ntp tracking bugs for this issue:
Affects: fedora-all [bug 1300277]
---
Statement:
This issue did not affect the versions of ntp as shipped with Red Hat Enterprise Linux 5, 6, and 7 as they do not include the affected code, which w
http://www.debian.org/security/2017/dsa-3775http://www.securityfocus.com/bid/95852http://www.securitytracker.com/id/1037755https://access.redhat.com/errata/RHSA-2017:1871https://security.gentoo.org/glsa/201702-30https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1494526.htmlhttp://www.debian.org/security/2017/dsa-3775http://www.securityfocus.com/bid/95852http://www.securitytracker.com/id/1037755https://access.redhat.com/errata/RHSA-2017:1871https://security.gentoo.org/glsa/201702-30https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1494526.html
2017-01-28
Published