PT-2024-6095 · Libpcap+4 · Libpcap+4

Flavio Toffalini

+1

·

Published

2024-08-30

·

Updated

2026-05-18

·

CVE-2024-8006

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libpcap (affected versions not specified)
Description The issue is related to a null pointer dereference in the pcap findalldevs ex() function of the libpcap library. This function becomes available when a user builds libpcap with remote packet capture support enabled. The function takes a filesystem path as an argument, which is expected to be a directory with input data files. If the specified path cannot be used as a directory, the opendir() function returns NULL, but this return value is not checked, and the NULL value is passed to readdir(), causing a null pointer dereference. This can allow an attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2025-2493
ALT-PU-2025-2535
AZL-48409
AZL-48412
AZL-48438
AZL-48462
BDU:2024-07003
CLEANSTART-2026-KY75084
CLEANSTART-2026-TO88856
CVE-2024-8006
MGASA-2024-0295
OESA-2024-2180
OPENSUSE-SU-2024:14309-1
OPENSUSE-SU-2024_3210-1
OPENSUSE-SU-2024_3217-1
OPENSUSE-SU-2024_3516-1
SUSE-SU-2024:3210-1
SUSE-SU-2024:3217-1
SUSE-SU-2024:3355-1
SUSE-SU-2024:3516-1
SUSE-SU-2025:20059-1
SUSE-SU-2026:20064-1

Affected Products

Alt Linux
Debian
Red Os
Suse
Libpcap