CVE-2018-14879
published 2019-10-03CVE-2018-14879: The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
PriorityP432high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
EPSS
4.67%
90.7th percentile
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.15.2 | 10.15.2 |
| apple | macos_catalina_10.15.2_security_update_2019-002_mojave_security_update_2019-007 | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tcpdump | < tcpdump 4.9.3-1 (bookworm) | tcpdump 4.9.3-1 (bookworm) |
| f5 | traffix_signaling_delivery_controller | 5.0.0 – 5.1.0 | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| tcpdump | tcpdump | < 4.9.3 | 4.9.3 |
| tcpdump | tcpdump | >= 0 < 4.9.3-1 | 4.9.3-1 |
| tcpdump | tcpdump | >= 0 < 4.9.3-1 | 4.9.3-1 |
| tcpdump | tcpdump | >= 0 < 4.9.3-1 | 4.9.3-1 |
| tcpdump | tcpdump | >= 0 < 4.9.3-1 | 4.9.3-1 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
tcpdump vulnerabilities
vendor_ubuntu·2020-01-27
CVE-2017-16808 tcpdump vulnerabilities
Title: tcpdump vulnerabilities
Summary: Several security issues were fixed in tcpdump.
USN-4252-1 fixed several vulnerabilities in tcpdump. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Multiple security issues were discovered in tcpdump. A remote attacker
could use these issues to cause tcpdump to crash, resulting in a denial of
service, or possibly execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Ubuntu
tcpdump vulnerabilities
vendor_ubuntu·2020-01-27
CVE-2017-16808 tcpdump vulnerabilities
Title: tcpdump vulnerabilities
Summary: Several security issues were fixed in tcpdump.
Multiple security issues were discovered in tcpdump. A remote attacker
could use these issues to cause tcpdump to crash, resulting in a denial of
service, or possibly execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Apple
CVE-2018-14879: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
vendor_apple·2019-12-10·CVSS 7.0
CVE-2018-14879 [HIGH] CVE-2018-14879: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Apple Security Update: About the security content of macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Product: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
CVE: CVE-2018-14879
Component: CVE-2018-14879
Red Hat
tcpdump: Out of bounds read/write in in get_next_file() in tcpdump.c
vendor_redhat·2019-10-02·CVSS 7.0
CVE-2018-14879 [HIGH] CWE-119 tcpdump: Out of bounds read/write in in get_next_file() in tcpdump.c
tcpdump: Out of bounds read/write in in get_next_file() in tcpdump.c
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
An out-of-bounds write vulnerability was discovered in tcpdump while reading the file passed to the -V option of the command line program. An attacker may abuse this flaw by tricking a victim user into using a malicious file with the -V option, which would make the program read one byte before a stack-based allocated buffer and potentially write a NULL byte to it.
Package: tcpdump (Red Hat Enterprise Linux 5) - Out of support scope
Package: tcpdump (Red Hat Enterprise Linux 6) - Out of support scope
Package: tcpdump (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2018-14879: tcpdump - The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow i...
vendor_debian·2018·CVSS 7.0
CVE-2018-14879 [HIGH] CVE-2018-14879: tcpdump - The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow i...
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
Scope: local
bookworm: resolved (fixed in 4.9.3-1)
bullseye: resolved (fixed in 4.9.3-1)
forky: resolved (fixed in 4.9.3-1)
sid: resolved (fixed in 4.9.3-1)
trixie: resolved (fixed in 4.9.3-1)
GHSA
GHSA-x5g3-55pg-9g4m: The command-line argument parser in tcpdump before 4
ghsa_unreviewed·2022-05-24
CVE-2018-14879 [MEDIUM] CWE-120 GHSA-x5g3-55pg-9g4m: The command-line argument parser in tcpdump before 4
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
OSV
CVE-2018-14879: The command-line argument parser in tcpdump before 4
osv·2019-10-03·CVSS 7.0
CVE-2018-14879 [HIGH] CVE-2018-14879: The command-line argument parser in tcpdump before 4
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
No detection rules found.
No public exploits indexed.
HackerOne
tcpdump: CVE-2018-14879 - buffer overflow in tcpdump.c:get_next_file()
hackerone·2020-02-13·CVSS 7.0
CVE-2018-14879 [HIGH] tcpdump: CVE-2018-14879 - buffer overflow in tcpdump.c:get_next_file()
tcpdump: CVE-2018-14879 - buffer overflow in tcpdump.c:get_next_file()
The release of tcpdump 4.9.3 brought many bug fixes, including one I submitted, CVE-2018-14879.
`The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().`
```
==2288==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7ffe363769bf at pc 0x56336d544e69 bp 0x7ffe36376260 sp 0x7ffe36376258
READ of size 1 at 0x7ffe363769bf thread T0
#0 0x56336d544e68 in get_next_file tcpdump.c:853
#1 0x56336d53ab63 in main tcpdump.c:1956
#2 0x7f83cae7c2e0 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x202e0)
#3 0x56336d543169 in _start (/root/tcpdump/tcpdump+0x16d169)
Address 0x7ffe363769bf is located in stack of thread T0 at offset 1727 in frame
#0 0x56336d53828f in
Bugzilla
CVE-2018-10105 CVE-2018-14461 CVE-2018-14462 CVE-2018-14463 CVE-2018-14464 CVE-2018-14465 CVE-2018-14466 CVE-2018-14467 CVE-2018-14468 CVE-2018-14469 CVE-2018-14470 CVE-2018-14879 CVE-2018-14880 CVE-2
bugzilla·2019-10-11·CVSS 9.8
CVE-2018-10105 [CRITICAL] CVE-2018-10105 CVE-2018-14461 CVE-2018-14462 CVE-2018-14463 CVE-2018-14464 CVE-2018-14465 CVE-2018-14466 CVE-2018-14467 CVE-2018-14468 CVE-2018-14469 CVE-2018-14470 CVE-2018-14879 CVE-2018-14880 CVE-2
CVE-2018-10105 CVE-2018-14461 CVE-2018-14462 CVE-2018-14463 CVE-2018-14464 CVE-2018-14465 CVE-2018-14466 CVE-2018-14467 CVE-2018-14468 CVE-2018-14469 CVE-2018-14470 CVE-2018-14879 CVE-2018-14880 CVE-2018-14881 ... tcpdump: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevan
Bugzilla
CVE-2018-14879 tcpdump: Out of bounds read/write in in get_next_file() in tcpdump.c
bugzilla·2019-10-10·CVSS 7.0
CVE-2018-14879 [HIGH] CVE-2018-14879 tcpdump: Out of bounds read/write in in get_next_file() in tcpdump.c
CVE-2018-14879 tcpdump: Out of bounds read/write in in get_next_file() in tcpdump.c
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/9ba91381954ad325ea4fd26b9c65a8bd9a2a85b6
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
tcpdump provides the `V` flag when you want to provide a list of filenames to use, either by stdin or by reading the content of a file. The attack scenario for this flaw is an attacker who tricks a victim user into executing `tcpdump -V` on a malicious file with a NULL byte as a first byte. This would make th
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00053.htmlhttp://seclists.org/fulldisclosure/2019/Dec/26https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGEShttps://github.com/the-tcpdump-group/tcpdump/commit/9ba91381954ad325ea4fd26b9c65a8bd9a2a85b6https://lists.debian.org/debian-lts-announce/2019/10/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62XY42U6HY3H2APR5EHNWCZ7SAQNMMJN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNYXF3IY2X65IOD422SA6EQUULSGW7FN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R2UDPOSGVJQIYC33SQBXMDXHH4QDSDMU/https://seclists.org/bugtraq/2019/Dec/23https://seclists.org/bugtraq/2019/Oct/28https://security.netapp.com/advisory/ntap-20200120-0001/https://support.apple.com/kb/HT210788https://support.f5.com/csp/article/K51512510?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4252-1/https://usn.ubuntu.com/4252-2/https://www.debian.org/security/2019/dsa-4547http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00053.htmlhttp://seclists.org/fulldisclosure/2019/Dec/26https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGEShttps://github.com/the-tcpdump-group/tcpdump/commit/9ba91381954ad325ea4fd26b9c65a8bd9a2a85b6https://lists.debian.org/debian-lts-announce/2019/10/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62XY42U6HY3H2APR5EHNWCZ7SAQNMMJN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNYXF3IY2X65IOD422SA6EQUULSGW7FN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R2UDPOSGVJQIYC33SQBXMDXHH4QDSDMU/https://seclists.org/bugtraq/2019/Dec/23https://seclists.org/bugtraq/2019/Oct/28https://security.netapp.com/advisory/ntap-20200120-0001/https://support.apple.com/kb/HT210788https://support.f5.com/csp/article/K51512510?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4252-1/https://usn.ubuntu.com/4252-2/https://www.debian.org/security/2019/dsa-4547
2019-10-03
Published