CVE-2017-11108
published 2017-07-08CVE-2017-11108: tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash…
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.90%
91.1th percentile
tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20 | — | — |
| debian | tcpdump | < tcpdump 4.9.1-1 (bookworm) | tcpdump 4.9.1-1 (bookworm) |
| tcpdump | tcpdump | — | — |
| tcpdump | tcpdump | >= 0 < 4.9.1-1 | 4.9.1-1 |
| tcpdump | tcpdump | >= 0 < 4.9.1-1 | 4.9.1-1 |
| tcpdump | tcpdump | >= 0 < 4.9.1-1 | 4.9.1-1 |
| tcpdump | tcpdump | >= 0 < 4.9.1-1 | 4.9.1-1 |
| tcpdump | tcpdump | >= 0 < 4.9.2-0ubuntu0.14.04.1 | 4.9.2-0ubuntu0.14.04.1 |
| tcpdump | tcpdump | >= 0 < 4.9.2-0ubuntu0.16.04.1 | 4.9.2-0ubuntu0.16.04.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2017-11108: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
vendor_apple·2017-10-31·CVSS 7.5
CVE-2017-11108 [HIGH] CVE-2017-11108: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
Product: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
CVE: CVE-2017-11108
Component: CVE-2017-11108
Ubuntu
tcpdump vulnerabilities
vendor_ubuntu·2017-09-14·CVSS 7.5
CVE-2017-11108 [HIGH] tcpdump vulnerabilities
Title: tcpdump vulnerabilities
Summary: Several security issues were fixed in tcpdump.
Wilfried Kirsch discovered a buffer overflow in the SLIP decoder
in tcpdump. A remote attacker could use this to cause a denial
of service (application crash) or possibly execute arbitrary
code. (CVE-2017-11543)
Bhargava Shastry discovered a buffer overflow in the bitfield converter
utility function bittok2str_internal() in tcpdump. A remote attacker
could use this to cause a denial of service (application crash)
or possibly execute arbitrary code. (CVE-2017-13011)
Otto Airamo and Antti Levomäki discovered logic errors in different
protocol parsers in tcpdump that could lead to an infinite loop. A
remote attacker could use these to cause a denial of service
(application hang). CVE-2017-12989, CVE-201
Ubuntu
tcpdump vulnerabilities
vendor_ubuntu·2017-09-14·CVSS 7.5
CVE-2017-11108 [HIGH] tcpdump vulnerabilities
Title: tcpdump vulnerabilities
Summary: Several security issues were fixed in tcpdump
USN-3415-1 fixed vulnerabilities in tcpdump for Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, and Ubuntu 17.04. This update provides the
corresponding tcpdump update for Ubuntu 12.04 ESM.
Original advisory details:
Wilfried Kirsch discovered a buffer overflow in the SLIP decoder
in tcpdump. A remote attacker could use this to cause a denial
of service (application crash) or possibly execute arbitrary
code. (CVE-2017-11543)
Bhargava Shastry discovered a buffer overflow in the bitfield converter
utility function bittok2str_internal() in tcpdump. A remote attacker
could use this to cause a denial of service (application crash)
or possibly execute arbitrary code. (CVE-2017-13011)
Otto Airamo and Antti Levomäki di
Red Hat
tcpdump: Heap buffer overflow in the EXTRACT_16BITS function
vendor_redhat·2017-07-07·CVSS 7.5
CVE-2017-11108 [HIGH] CWE-122 tcpdump: Heap buffer overflow in the EXTRACT_16BITS function
tcpdump: Heap buffer overflow in the EXTRACT_16BITS function
tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.
Package: tcpdump (Red Hat Enterprise Linux 5) - Will not fix
Package: tcpdump (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2017-11108: tcpdump - tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based b...
vendor_debian·2017·CVSS 7.5
CVE-2017-11108 [HIGH] CVE-2017-11108: tcpdump - tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based b...
tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.
Scope: local
bookworm: resolved (fixed in 4.9.1-1)
bullseye: resolved (fixed in 4.9.1-1)
forky: resolved (fixed in 4.9.1-1)
sid: resolved (fixed in 4.9.1-1)
trixie: resolved (fixed in 4.9.1-1)
GHSA
GHSA-rr85-pcqj-p9q5: tcpdump 4
ghsa_unreviewed·2022-05-13
CVE-2017-11108 [HIGH] CWE-125 GHSA-rr85-pcqj-p9q5: tcpdump 4
tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.
OSV
tcpdump vulnerabilities
osv·2017-09-14·CVSS 7.5
CVE-2017-11543 [HIGH] tcpdump vulnerabilities
tcpdump vulnerabilities
Wilfried Kirsch discovered a buffer overflow in the SLIP decoder
in tcpdump. A remote attacker could use this to cause a denial
of service (application crash) or possibly execute arbitrary
code. (CVE-2017-11543)
Bhargava Shastry discovered a buffer overflow in the bitfield converter
utility function bittok2str_internal() in tcpdump. A remote attacker
could use this to cause a denial of service (application crash)
or possibly execute arbitrary code. (CVE-2017-13011)
Otto Airamo and Antti Levomäki discovered logic errors in different
protocol parsers in tcpdump that could lead to an infinite loop. A
remote attacker could use these to cause a denial of service
(application hang). CVE-2017-12989, CVE-2017-12990, CVE-2017-12995,
CVE-2017-12997)
Otto Airamo, Brian Car
OSV
CVE-2017-11108: tcpdump 4
osv·2017-07-08·CVSS 7.5
CVE-2017-11108 [HIGH] CVE-2017-11108: tcpdump 4
tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-11108 tcpdump: Heap buffer overflow in the EXTRACT_16BITS function [fedora-all]
bugzilla·2017-07-19·CVSS 7.5
CVE-2017-11108 [HIGH] CVE-2017-11108 tcpdump: Heap buffer overflow in the EXTRACT_16BITS function [fedora-all]
CVE-2017-11108 tcpdump: Heap buffer overflow in the EXTRACT_16BITS function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2017-11108 tcpdump: Heap buffer overflow in the EXTRACT_16BITS function
bugzilla·2017-07-19·CVSS 7.5
CVE-2017-11108 [HIGH] CVE-2017-11108 tcpdump: Heap buffer overflow in the EXTRACT_16BITS function
CVE-2017-11108 tcpdump: Heap buffer overflow in the EXTRACT_16BITS function
tcpdump allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1468504
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1472879]
---
According to NVD, CVSSv3 score is actually 7.5, not 3.3:
https://nvd.nist.gov/vuln/detail/CVE-2017-11108
CVSS v3 Base Score:
7.5 High
Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Impact Score:
3.6
Exploitability Score:
3.9
Could you reconsider?
---
(In reply to Dominik Mierzejewski from comment
http://www.debian.org/security/2017/dsa-3971https://access.redhat.com/errata/RHEA-2018:0705https://bugzilla.redhat.com/show_bug.cgi?id=1468504https://security.gentoo.org/glsa/201709-23https://support.apple.com/HT208221http://www.debian.org/security/2017/dsa-3971https://access.redhat.com/errata/RHEA-2018:0705https://bugzilla.redhat.com/show_bug.cgi?id=1468504https://security.gentoo.org/glsa/201709-23https://support.apple.com/HT208221
2017-07-08
Published