Executive brief
tcpdump is a widely used command-line tool for monitoring and analyzing network traffic. A vulnerability in its Spanning Tree Protocol (STP) parser allows an attacker to send specially crafted network packets that can cause the application to crash or potentially execute unauthorized code. This could lead to a disruption of network monitoring services or provide a foothold for further attacks on the system running the tool.
Technical details
A buffer overflow vulnerability exists in the Spanning Tree Protocol (STP) parser of tcpdump versions prior to 4.9.0. The flaw is located within multiple functions in the 'print-stp.c' source file. A remote attacker can exploit this by sending specially crafted STP packets to a network segment where tcpdump is performing live capture, or by tricking a user into opening a malicious pcap file. Successful exploitation can lead to a denial of service (application crash) or arbitrary code execution with the privileges of the tcpdump process. The issue was addressed in version 4.9.0.
Affected products
- tcpdump tcpdump before 4.9.0
Timeline
- 2017-01-27: advisory: NVD publication date
- 2017-01-29: patched: Debian released fixed version 4.9.0-1