The command-line argument parser in tcpdump before 4.99.0 has a...
Vulnerability Description
The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-16301
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Include Security and Mozilla Secure Open Source program
References
More from The Tcpdump Group
View All →Affected Vendor
The Tcpdump Group
View all reports →