9.8
CVSSv3

CVE-2017-11542

Published: 23/07/2017 Updated: 03/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

tcpdump 4.9.0 has a heap-based buffer over-read in the pimv1_print function in print-pim.c.

Vulnerable Product Search on Vulmon Subscribe to Product

tcpdump tcpdump 4.9.0

Vendor Advisories

Several security issues were fixed in tcpdump ...
Several security issues were fixed in tcpdump ...
Several vulnerabilities have been discovered in tcpdump, a command-line network traffic analyzer These vulnerabilities might result in denial of service or, potentially, execution of arbitrary code For the oldstable distribution (jessie), these problems have been fixed in version 492-1~deb8u1 For the stable distribution (stretch), these proble ...
Debian Bug report logs - #867718 CVE-2017-11108 Package: tcpdump; Maintainer for tcpdump is Romain Francoise <rfrancoise@debianorg>; Source for tcpdump is src:tcpdump (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 8 Jul 2017 21:27:02 UTC Severity: important Tags: fixed-upstream, ...
Debian Bug report logs - #873806 CVE-2017-11543 Package: tcpdump; Maintainer for tcpdump is Romain Francoise <rfrancoise@debianorg>; Source for tcpdump is src:tcpdump (PTS, buildd, popcon) Reported by: Guido Günther <agx@sigxcpuorg> Date: Thu, 31 Aug 2017 10:42:11 UTC Severity: important Tags: security, upstream ...
Debian Bug report logs - #873804 CVE-2017-11541 Package: tcpdump; Maintainer for tcpdump is Romain Francoise <rfrancoise@debianorg>; Source for tcpdump is src:tcpdump (PTS, buildd, popcon) Reported by: Guido Günther <agx@sigxcpuorg> Date: Thu, 31 Aug 2017 10:42:02 UTC Severity: important Tags: security, upstream ...
Debian Bug report logs - #873805 CVE-2017-11542 Package: tcpdump; Maintainer for tcpdump is Romain Francoise <rfrancoise@debianorg>; Source for tcpdump is src:tcpdump (PTS, buildd, popcon) Reported by: Guido Günther <agx@sigxcpuorg> Date: Thu, 31 Aug 2017 10:42:05 UTC Severity: important Tags: security, upstream ...
tcpdump 490 has a heap-based buffer over-read in the pimv1_print function in print-pimc ...
A heap-based out-of-bounds read vulnerability was discovered in tcpdump <= 491, in the pimv1_print function in print-pimc An attacker could craft a malicious pcap file or send specially crafted packets to the network that would cause tcpdump to crash when attempting to print a summary of the packet data ...