Lucene search

K
cvelistTcpdumpCVELIST:CVE-2018-16301
HistoryOct 03, 2019 - 3:55 p.m.

CVE-2018-16301

2019-10-0315:55:20
CWE-190
CWE-787
Tcpdump
www.cve.org
3

7.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.2%

The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.

CNA Affected

[
  {
    "product": "tcpdump",
    "vendor": "The Tcpdump Group",
    "versions": [
      {
        "lessThan": "4.99.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]