cbcvebase.
CVE-2024-8006
published 2024-08-31

CVE-2024-8006: Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions…

PriorityP416medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.22%
12.5th percentile
Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions that become available is pcap_findalldevs_ex(). One of the function arguments can be a filesystem path, which normally means a directory with input data files. When the specified path cannot be used as a directory, the function receives NULL from opendir(), but does not check the return value and passes the NULL value to readdir(), which causes a NULL pointer derefence.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlibpcap< libpcap 1.10.5-1 (forky)libpcap 1.10.5-1 (forky)
msrcazl3_libpcap_1.10.4-1_on_azure_linux_3.0
msrcazl3_libpcap_1.10.5-1_on_azure_linux_3.0
msrcazl3_nmap_7.95-2_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_libpcap_1.10.1-3_on_cbl_mariner_2.0
msrccbl2_libpcap_1.10.1-4_on_cbl_mariner_2.0
msrccbl2_nmap_7.93-3_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
tcpdumplibpcap< 1.10.51.10.5
tcpdumplibpcap>= 0 < 1.10.5-11.10.5-1
tcpdumplibpcap>= 0 < 1.10.5-11.10.5-1
the_tcpdump_grouplibpcap
the_tcpdump_grouplibpcap1.10.x – 1.10.4

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
osv4.4MEDIUM
vendor_debian4.4LOW
vendor_msrc4.4MEDIUM
vendor_oracle4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.