Related Vulnerabilities: CVE-2017-11541  

A heap-based out-of-bounds read vulnerability was discovered in tcpdump <= 4.9.1, in the lldp_print function in print-lldp.c, related to util-print.c. An attacker could craft a malicious pcap file or send specially crafted packets to the network that would cause tcpdump to crash when attempting to print a summary of the packet data.

Severity Medium

Remote Yes

Type Denial of service

Description

A heap-based out-of-bounds read vulnerability was discovered in tcpdump <= 4.9.1, in the lldp_print function in print-lldp.c, related to util-print.c. An attacker could craft a malicious pcap file or send specially crafted packets to the network that would cause tcpdump to crash when attempting to print a summary of the packet data.

AVG-361 tcpdump 4.9.1-1 4.9.2-1 Critical Fixed

13 Sep 2017 ASA-201709-5 AVG-361 tcpdump Critical multiple issues

https://github.com/hackerlib/hackerlib-vul/tree/master/tcpdump-vul/heap-buffer-overflow/util-print
https://github.com/the-tcpdump-group/tcpdump/commit/21d702a136c5c16882e368af7c173df728242280