PT-2019-9294 · Tcpdump+5 · Tcpdump+6

Published

2019-09-30

·

Updated

2025-08-06

·

CVE-2018-16301

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions tcpdump versions prior to 4.99.0 tcpdump versions prior to 4.9.3
Description The issue is related to a buffer overflow in the command-line argument parser of tcpdump, specifically in the read infile() function in tcpdump.c. This can be triggered by an attacker creating a large file (4GB) on the local filesystem and specifying its name as the value of the -F command-line argument. The vulnerability also involves a buffer overflow and/or over-read in libpcap, as used in tcpdump.
Recommendations For versions prior to 4.99.0, update to version 4.99.0 or later to resolve the issue. For versions prior to 4.9.3, update to version 4.9.3 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the -F command-line argument with large files until a patch is available.

Fix

Memory Corruption

Integer Overflow

Out of bounds Read

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3119
ALT-PU-2019-3120
ALT-PU-2020-3562
ALT-PU-2020-3563
ALT-PU-2021-1432
ALT-PU-2021-1433
ALT-PU-2023-2035
ALT-PU-2024-15273
ALT-PU-2024-15770
ALT-PU-2024-8987
AZL-8506
BDU:2025-11760
CVE-2018-16301
MGASA-2019-0297
OESA-2022-1862
OESA-2022-1863
OPENSUSE-SU-2019:2343-1
OPENSUSE-SU-2019:2344-1
OPENSUSE-SU-2019:2345-1
OPENSUSE-SU-2019:2348-1
OPENSUSE-SU-2019_2343-1
OPENSUSE-SU-2019_2344-1
OPENSUSE-SU-2019_2345-1
OPENSUSE-SU-2019_2348-1
OPENSUSE-SU-2022:0774-1
OPENSUSE-SU-2022_0774-1
OPENSUSE-SU-2024:10969-1
OPENSUSE-SU-2024:11425-1
ROSA-SA-2025-2660
SUSE-SU-2019:14191-1
SUSE-SU-2019:2669-1
SUSE-SU-2019:2673-1
SUSE-SU-2019:2674-1
SUSE-SU-2019_14191-1
SUSE-SU-2019_2669-1
SUSE-SU-2019_2673-1
SUSE-SU-2020:3360-1
SUSE-SU-2022:0505-1
SUSE-SU-2022:0774-1
SUSE-SU-2022:14890-1
SUSE-SU-2022_0505-1
SUSE-SU-2022_0774-1
SUSE-SU-2022_14890-1
USN-5331-1
USN-5331-2

Affected Products

Alt Linux
Linuxmint
Red Os
Suse
Ubuntu
Libpcap
Tcpdump