6.4
CVSSv2

CVE-2014-8769

Published: 20/11/2014 Updated: 09/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

tcpdump 3.8 up to and including 4.6.2 might allow remote malicious users to obtain sensitive information from memory or cause a denial of service (packet loss or segmentation fault) via a crafted Ad hoc On-Demand Distance Vector (AODV) packet, which triggers an out-of-bounds memory access.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat tcpdump 3.8.0

redhat tcpdump 3.8.2

redhat tcpdump 3.9.8

redhat tcpdump 4.0.0

redhat tcpdump 4.4.0

redhat tcpdump 4.5.0

redhat tcpdump 3.9.4

redhat tcpdump 3.9.5

redhat tcpdump 4.1.2

redhat tcpdump 4.2.1

redhat tcpdump 4.6.0

redhat tcpdump 4.6.1

redhat tcpdump 3.9.2

redhat tcpdump 3.9.3

redhat tcpdump 4.1.0

redhat tcpdump 4.1.1

redhat tcpdump 4.5.1

redhat tcpdump 4.5.2

redhat tcpdump 3.9.6

redhat tcpdump 3.9.7

redhat tcpdump 4.3.0

redhat tcpdump 4.3.1

redhat tcpdump 4.6.2

Vendor Advisories

Several security issues were fixed in tcpdump ...
Several vulnerabilities have been discovered in tcpdump, a command-line network traffic analyzer These vulnerabilities might result in denial of service, leaking sensitive information from memory or, potentially, execution of arbitrary code For the stable distribution (wheezy), these problems have been fixed in version 430-1+deb7u1 For the upc ...
Debian Bug report logs - #770415 tcpdump: CVE-2014-8768: denial of service in verbose mode using malformed Geonet payload Package: tcpdump; Maintainer for tcpdump is Romain Francoise <rfrancoise@debianorg>; Source for tcpdump is src:tcpdump (PTS, buildd, popcon) Reported by: Nguyen Cong <congnguyenthe@toshiba-tsdvcom&g ...
Debian Bug report logs - #770424 tcpdump: CVE-2014-8769: unreliable output using malformed AOVD payload Package: tcpdump; Maintainer for tcpdump is Romain Francoise <rfrancoise@debianorg>; Source for tcpdump is src:tcpdump (PTS, buildd, popcon) Reported by: Nguyen Cong <congnguyenthe@toshiba-tsdvcom> Date: Fri, 21 ...
Debian Bug report logs - #770434 tcpdump: CVE-2014-8767: tcpdump denial of service in verbose mode using malformed OLSR payload Package: tcpdump; Maintainer for tcpdump is Romain Francoise <rfrancoise@debianorg>; Source for tcpdump is src:tcpdump (PTS, buildd, popcon) Reported by: Nguyen Cong <congnguyenthe@toshiba-tsdv ...
tcpdump 38 through 462 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet loss or segmentation fault) via a crafted Ad hoc On-Demand Distance Vector (AODV) packet, which triggers an out-of-bounds memory access ...

Exploits

It was found out that malformed network traffic (AOVD-based) can lead to an abnormal behavior if verbose output of tcpdump monitoring the network is used Affected versions are 38 through 462 ...