The Tcpdump Group Tcpdump vulnerabilities

5 known vulnerabilities affecting the_tcpdump_group/tcpdump.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2024-2397MEDIUMCVSS 6.2≥ 0d4083e, < b9811ef2024-04-12
CVE-2024-2397 [MEDIUM] CWE-835 CVE-2024-2397: Due to a bug in packet data buffers management, the PPP printer in tcpdump can enter an infinite loo Due to a bug in packet data buffers management, the PPP printer in tcpdump can enter an infinite loop when reading a crafted DLT_PPP_SERIAL .pcap savefile. This problem does not affect any tcpdump release, but it affected the git master branch from 2023-06-05 to 2024-03-21.
cvelistv5nvd
CVE-2023-1801MEDIUMCVSS 6.5v4.99.32023-04-07
CVE-2023-1801 [MEDIUM] CWE-787 CVE-2023-1801: The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet.
cvelistv5nvd
CVE-2020-8036HIGHCVSS 7.5v4.10.0-PRE-GIT2020-11-04
CVE-2020-8036 [HIGH] CWE-125 CVE-2020-8036: The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe w The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way.
cvelistv5nvd
CVE-2020-8037HIGHCVSS 7.5v4.9.32020-11-04
CVE-2020-8037 [HIGH] CWE-770 CVE-2020-8037: The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
cvelistv5nvd
CVE-2018-16301HIGHCVSS 7.8≥ unspecified, < 4.99.02019-10-03
CVE-2018-16301 [HIGH] CWE-190 CVE-2018-16301: The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_in The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.
cvelistv5nvd