PT-2018-3760 · Tcpdump+7 · Tcpdump+7

Zyingp

·

Published

2018-11-25

·

Updated

2024-06-15

·

CVE-2018-19519

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions tcpdump version 4.9.2
Description A stack-based buffer over-read issue exists in the print prefix function of print-hncp.c due to missing initialization, which can be triggered by crafted packet data. This may allow a remote attacker to access confidential data.
Recommendations For tcpdump version 4.9.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3120
ALT-PU-2020-3563
ALT-PU-2021-1433
BDU:2021-05290
CESA-2019_3976
CESA-2020_1604
CVE-2018-19519
ECHO-73F3-1173-C1CB
MGASA-2018-0492
OPENSUSE-SU-2018_4144-1
OPENSUSE-SU-2018_4252-1
OPENSUSE-SU-2024:11425-1
RHSA-2019:3976
RHSA-2019_3976
RHSA-2020:1604
RHSA-2020_1604
SUSE-SU-2018:4131-1
SUSE-SU-2018:4149-1
SUSE-SU-2018_4131-1
SUSE-SU-2018_4149-1
USN-4252-1
USN-4252-2

Affected Products

Alt Linux
Centos
Debian
Ibm Aix
Red Hat
Suse
Ubuntu
Tcpdump