PT-2019-4099 · Tcpdump+7 · Tcpdump+7

Published

2019-09-30

·

Updated

2024-06-15

·

CVE-2018-10105

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions tcpdump versions prior to 4.9.3
Description The issue is related to insufficient input validation in the tcpdump utility, which can be exploited by a remote attacker to gain unauthorized access to information and compromise its integrity and availability. The vulnerability specifically affects the handling of SMB data and is also related to a heap-based buffer over-read.
Recommendations For versions prior to 4.9.3, update to version 4.9.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the tcpdump utility to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3120
ALT-PU-2020-3563
ALT-PU-2021-1433
BDU:2019-04667
BDU:2020-04923
CESA-2020_4760
CVE-2018-10105
DLA-1955-1
DSA-4547-1
MGASA-2019-0297
OPENSUSE-SU-2019:2344-1
OPENSUSE-SU-2019:2348-1
OPENSUSE-SU-2019_2344-1
OPENSUSE-SU-2019_2348-1
OPENSUSE-SU-2024:11425-1
RHSA-2020:4760
RHSA-2020_4760
RHSA-2021:2191
RLSA-2020:4760
SUSE-SU-2019:14191-1
SUSE-SU-2019:2674-1
SUSE-SU-2019_14191-1
SUSE-SU-2020:3360-1
USN-4252-1
USN-4252-2

Affected Products

Alt Linux
Centos
Ibm Aix
Red Hat
Rocky Linux
Suse
Ubuntu
Tcpdump