Junglewise Threat Intelligence

CVE-2016-7930: tcpdump buffer overflow in LLC/SNAP parser

CVE-2016-7930 · Severity: critical · CVSS 9.8 · Published 2017-01-28

Technologies: Tcpdump. Vendors: Tcpdump.

Executive brief

tcpdump is a widely used command-line tool for monitoring and analyzing network traffic. A vulnerability in its LLC/SNAP protocol parser allows an attacker to send specially crafted network packets that can cause the application to crash or potentially execute unauthorized code. This could lead to a denial of service or a compromise of the system running the monitoring software.

Technical details

A buffer overflow vulnerability exists in the LLC/SNAP parser within tcpdump versions prior to 4.9.0. The flaw is located in the llc_print() function in print-llc.c. An unauthenticated remote attacker can exploit this by sending specially crafted network packets to a segment where tcpdump is performing live capture, or by providing a malicious pcap file for analysis. Successful exploitation can result in a process crash (Denial of Service) or potentially arbitrary code execution with the privileges of the tcpdump process. The issue was addressed in version 4.9.0.

Affected products

  • tcpdump tcpdump before 4.9.0

Timeline

  • 2017-01-26: patched: tcpdump 4.9.0 released fixing multiple vulnerabilities
  • 2017-01-27: advisory: NVD published CVE-2016-7930

References

Related threats