Executive brief
tcpdump is a widely used command-line tool for monitoring and analyzing network traffic. A vulnerability in its GRE protocol parser allows an attacker to send specially crafted network packets that can cause the application to crash or potentially execute unauthorized code. This could lead to a denial of service or a compromise of the system running the network analysis tool.
Technical details
A buffer overflow vulnerability exists in the GRE (Generic Routing Encapsulation) parser of tcpdump versions prior to 4.9.0. The flaw is located within multiple functions in the print-gre.c source file. A remote, unauthenticated attacker can exploit this by sending specially crafted GRE packets to a network segment where tcpdump is performing live capture, or by tricking a user into opening a malicious pcap file. Successful exploitation can result in a crash (Denial of Service) or potentially arbitrary code execution with the privileges of the tcpdump process. The issue was addressed in version 4.9.0.
Affected products
- tcpdump tcpdump < 4.9.0
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory
- 2017-01-28: patched: Fixed in version 4.9.0-1 in Debian and upstream 4.9.0