CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
Low
Remote packet capture support is disabled by default in libpcap. When a
user builds libpcap with remote packet capture support enabled, one of the
functions that become available is pcap_findalldevs_ex(). One of the
function arguments can be a filesystem path, which normally means a
directory with input data files. When the specified path cannot be used as
a directory, the function receives NULL from opendir(), but does not check
the return value and passes the NULL value to readdir(), which causes a
NULL pointer derefence.
github.com/the-tcpdump-group/libpcap/commit/0f8a103469ce87d2b8d68c5130a46ddb7fb5eb29
github.com/the-tcpdump-group/libpcap/commit/0f8a103469ce87d2b8d68c5130a46ddb7fb5eb29 (master)
github.com/the-tcpdump-group/libpcap/commit/8a633ee5b9ecd9d38a587ac9b204e2380713b0d6
github.com/the-tcpdump-group/libpcap/commit/8a633ee5b9ecd9d38a587ac9b204e2380713b0d6 (libpcap-1.10.5)
launchpad.net/bugs/cve/CVE-2024-8006
nvd.nist.gov/vuln/detail/CVE-2024-8006
security-tracker.debian.org/tracker/CVE-2024-8006
www.cve.org/CVERecord?id=CVE-2024-8006