CVE-2020-8037Allocation of Resources Without Limits or Throttling in Tcpdump Group Tcpdump

Severity
7.5HIGHNVD
OSV7.8
EPSS
0.3%
top 49.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 4
Latest updateMay 24

Description

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

Debiantcpdump/tcpdump< 4.9.3-7+3
Ubuntutcpdump/tcpdump< 4.9.3-0ubuntu0.18.04.2+2
NVDtcpdump/tcpdump4.9.3
CVEListV5the_tcpdump_group/tcpdump4.9.3
NVDapple/macos11.011.3

Also affects: Debian Linux 9.0, Fedora 32, 33

Patches

🔴Vulnerability Details

5
GHSA
GHSA-qggh-75q9-j3rf: The ppp decapsulator in tcpdump 42022-05-24
OSV
tcpdump vulnerabilities2022-04-11
OSV
tcpdump vulnerabilities2022-03-16
OSV
CVE-2020-8037: The ppp decapsulator in tcpdump 42020-11-04
CVEList
ppp decapsulator can be convinced to allocate a large amount of memory2020-11-04

📋Vendor Advisories

7
Ubuntu
tcpdump vulnerabilities2022-04-11
Ubuntu
tcpdump vulnerabilities2022-03-16
Apple
CVE-2020-8037: macOS Big Sur 11.32021-04-26
Apple
CVE-2020-8037: Security Update 2021-002 Catalina2021-04-26
Microsoft
ppp decapsulator can be convinced to allocate a large amount of memory2020-11-10
CVE-2020-8037 — THE Tcpdump Group Tcpdump vulnerability | cvebase