PT-2014-8724 · Tcpdump+3 · Tcpdump+3

Steffen Bauch

·

Published

2014-11-20

·

Updated

2024-06-15

·

CVE-2014-8769

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions tcpdump versions 3.8 through 4.6.2
Description The issue allows remote attackers to obtain sensitive information from memory or cause a denial of service, such as packet loss or segmentation fault, via a crafted Ad hoc On-Demand Distance Vector (AODV) packet. This packet triggers an out-of-bounds memory access.
Recommendations For versions 3.8 through 4.6.2, update to a version that fixes the out-of-bounds memory access issue to prevent potential attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8769
DLA-102-1
DSA-3086-1
MGASA-2014-0503
OPENSUSE-SU-2024:10396-1
SUSE-RU-2015:0335-1
SUSE-SU-2015:0692-1
SUSE-SU-2017:1110-1
USN-2433-1

Affected Products

Ibm Aix
Suse
Ubuntu
Tcpdump