tcpdump BGP integer overflow
Published Jul 16, 2007
9.8
CRITICALCVSS 3.1
EPSS 70.39%
Description
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
Affected products
No data.
Configuration 2
- 6.06
- 6.10
- 7.04
Configuration 3
- 3.1
- 4.0
Configuration 4
Configuration 5
- ≥ 5.0 · < 5.5
- ≥ 6.0 · < 6.1
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
Configuration 6
- ≥ 10.0.0 · < 10.4.11
- ≥ 10.0.0 · < 10.4.11
No data.
Red Hat Enterprise Linux 4
tcpdump-14:3.8.2-12.el4
Fixed · RHSA-2007:0387
Red Hat Enterprise Linux 5
tcpdump-14:3.9.4-11.el5
Fixed · RHSA-2007:0368
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | tcpdump-14:3.8.2-12.el4 | Fixed | RHSA-2007:0387 |
| Red Hat Enterprise Linux 5 | tcpdump-14:3.9.4-11.el5 | Fixed | RHSA-2007:0368 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the version of tcpdump shipped in Red Hat Enterprise Linux 2.1 or 3. Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=250275 The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: https://access.redhat.com/security/updates/classification/
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Oct 15, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 70.39% (0.70386) | 99.37th | v5 (v2026.06.15) |
| Jun 15, 2026 | 70.39% (0.70386) | 99.30th | v5 (v2026.06.15) |
| Sep 20, 2025 | 72.12% (0.72116) | 98.71th | v4 (v2025.03.14) |
| Mar 30, 2025 | 74.40% (0.74399) | 98.77th | v4 (v2025.03.14) |
| Mar 29, 2025 | 72.32% (0.72316) | 98.36th | v4 (v2025.03.14) |
| Mar 17, 2025 | 74.40% (0.74399) | 98.77th | v4 (v2025.03.14) |
| Dec 17, 2024 | 94.76% (0.94764) | 99.45th | v3 (v2023.03.01) |
| Apr 11, 2024 | 68.66% (0.68662) | 97.93th | v3 (v2023.03.01) |
| Jan 13, 2024 | 65.95% (0.65953) | 97.62th | v3 (v2023.03.01) |
| Dec 18, 2023 | 95.05% (0.95054) | 99.12th | v3 (v2023.03.01) |
| Mar 7, 2023 | 94.99% (0.94987) | 98.80th | v3 (v2023.03.01) |
| Mar 6, 2023 | 47.94% (0.47944) | 98.60th | v2 (v2022.01.01) |
| Feb 4, 2022 | 47.94% (0.47944) | 98.10th | v2 (v2022.01.01) |
References (39)
- http://bugs.gentoo.org/show_bug.cgi?id=184815 x_refsource_CONFIRMThird Party Advisory
- http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-bgp.c?r1=1.91.2.11&r2=1.91.2.12 x_refsource_MISCBroken Link
- http://docs.info.apple.com/article.html?artnum=307179 x_refsource_CONFIRMBroken Link
- http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html vendor-advisoryx_refsource_APPLEMailing List
- http://secunia.com/advisories/26135 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/26168 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/26223 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/26231 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/26263 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/26266 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/26286 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/26395 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/26404 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/26521 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/27580 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/28136 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://security.freebsd.org/advisories/FreeBSD-SA-07:06.tcpdump.asc vendor-advisoryx_refsource_FREEBSDThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200707-14.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.449313 vendor-advisoryx_refsource_SLACKWAREMailing ListPatch
- http://www.debian.org/security/2007/dsa-1353 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.digit-labs.org/files/exploits/private/tcpdump-bgp.c x_refsource_MISCExploit
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:148 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.novell.com/linux/security/advisories/2007_16_sr.html vendor-advisoryx_refsource_SUSEBroken Link
- http://www.redhat.com/support/errata/RHSA-2007-0368.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2007-0387.html vendor-advisoryx_refsource_REDHATBroken LinkVendor Advisory
- http://www.securityfocus.com/archive/1/474225/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/24965 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1018434 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.trustix.org/errata/2007/0023/ vendor-advisoryx_refsource_TRUSTIXBroken Link
- http://www.turbolinux.com/security/2007/TLSA-2007-46.txt vendor-advisoryx_refsource_TURBOBroken Link
- http://www.ubuntu.com/usn/usn-492-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA07-352A.html third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2007/2578 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2007/4238 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- https://access.redhat.com/security/cve/CVE-2007-3798 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=250275 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2007-3798
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9771 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2007-3798
| Link | Providers | Tags |
|---|---|---|
| http://bugs.gentoo.org/show_bug.cgi?id=184815 | x_refsource_CONFIRMThird Party Advisory | |
| http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-bgp.c?r1=1.91.2.11&r2=1.91.2.12 | x_refsource_MISCBroken Link | |
| http://docs.info.apple.com/article.html?artnum=307179 | x_refsource_CONFIRMBroken Link | |
| http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html | vendor-advisoryx_refsource_APPLEMailing List | |
| http://secunia.com/advisories/26135 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/26168 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/26223 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/26231 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/26263 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/26266 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/26286 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/26395 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/26404 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/26521 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/27580 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/28136 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://security.freebsd.org/advisories/FreeBSD-SA-07:06.tcpdump.asc | vendor-advisoryx_refsource_FREEBSDThird Party Advisory | |
| http://security.gentoo.org/glsa/glsa-200707-14.xml | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.449313 | vendor-advisoryx_refsource_SLACKWAREMailing ListPatch | |
| http://www.debian.org/security/2007/dsa-1353 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.digit-labs.org/files/exploits/private/tcpdump-bgp.c | x_refsource_MISCExploit | |
| http://www.mandriva.com/security/advisories?name=MDKSA-2007:148 | vendor-advisoryx_refsource_MANDRIVAThird Party Advisory | |
| http://www.novell.com/linux/security/advisories/2007_16_sr.html | vendor-advisoryx_refsource_SUSEBroken Link | |
| http://www.redhat.com/support/errata/RHSA-2007-0368.html | vendor-advisoryx_refsource_REDHATBroken Link | |
| http://www.redhat.com/support/errata/RHSA-2007-0387.html | vendor-advisoryx_refsource_REDHATBroken LinkVendor Advisory | |
| http://www.securityfocus.com/archive/1/474225/100/0/threaded | mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/24965 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id?1018434 | vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.trustix.org/errata/2007/0023/ | vendor-advisoryx_refsource_TRUSTIXBroken Link | |
| http://www.turbolinux.com/security/2007/TLSA-2007-46.txt | vendor-advisoryx_refsource_TURBOBroken Link | |
| http://www.ubuntu.com/usn/usn-492-1 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| http://www.us-cert.gov/cas/techalerts/TA07-352A.html | third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource | |
| http://www.vupen.com/english/advisories/2007/2578 | vdb-entryx_refsource_VUPENBroken LinkVendor Advisory | |
| http://www.vupen.com/english/advisories/2007/4238 | vdb-entryx_refsource_VUPENBroken LinkVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2007-3798 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=250275 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2007-3798 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9771 | vdb-entrysignaturex_refsource_OVALBroken Link | |
| https://www.cve.org/CVERecord?id=CVE-2007-3798 |
Change history (0)
No recorded changes yet.