Back

HIGH

tcpdump: Buffer overflow in the -F command line argument parser

Published Oct 3, 2019

Description

The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.

Affected products

Remediation

Red Hat statement

This flaw has been rated as having a security impact of Low. See the discussion on upstream issue https://github.com/the-tcpdump-group/libpcap/issues/855 for more information.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Tcpdump
Published Oct 3, 2019
Updated Aug 5, 2024
Reserved Aug 31, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 30, 2019