Junglewise Threat Intelligence

CVE-2016-7933: tcpdump buffer overflow in PPP parser

CVE-2016-7933 · Severity: critical · CVSS 9.8 · Published 2017-01-28

Technologies: Tcpdump. Vendors: Tcpdump.

Executive brief

tcpdump is a widely used command-line tool for monitoring and analyzing network traffic. A vulnerability in its PPP protocol parser allows an attacker to cause a system crash or potentially execute unauthorized code by sending specially crafted network packets. This could lead to a denial of service or a compromise of the system performing the network capture.

Technical details

A buffer overflow vulnerability exists in tcpdump's PPP (Point-to-Point Protocol) parser, specifically within the ppp_hdlc_if_print() function in print-ppp.c. The flaw is triggered when tcpdump processes specially crafted network packets or pcap files containing malicious PPP traffic. An unauthenticated remote attacker can exploit this by sending these packets to a network segment where tcpdump is running in live capture mode. Successful exploitation can result in a denial of service (application crash) or potentially arbitrary code execution with the privileges of the tcpdump process. The issue was addressed in version 4.9.0.

Affected products

  • tcpdump tcpdump before 4.9.0

Timeline

  • 2017-01-26: disclosed: Upstream release 4.9.0 announced fixing multiple vulnerabilities
  • 2017-01-27: advisory: NVD publication date
  • 2017-01-29: patched: Debian security update released

References

Related threats