Executive brief
tcpdump is a widely used command-line tool for monitoring and analyzing network traffic. A vulnerability in its PPP protocol parser allows an attacker to cause a system crash or potentially execute unauthorized code by sending specially crafted network packets. This could lead to a denial of service or a compromise of the system performing the network capture.
Technical details
A buffer overflow vulnerability exists in tcpdump's PPP (Point-to-Point Protocol) parser, specifically within the ppp_hdlc_if_print() function in print-ppp.c. The flaw is triggered when tcpdump processes specially crafted network packets or pcap files containing malicious PPP traffic. An unauthenticated remote attacker can exploit this by sending these packets to a network segment where tcpdump is running in live capture mode. Successful exploitation can result in a denial of service (application crash) or potentially arbitrary code execution with the privileges of the tcpdump process. The issue was addressed in version 4.9.0.
Affected products
- tcpdump tcpdump before 4.9.0
Timeline
- 2017-01-26: disclosed: Upstream release 4.9.0 announced fixing multiple vulnerabilities
- 2017-01-27: advisory: NVD publication date
- 2017-01-29: patched: Debian security update released