Executive brief
A vulnerability exists in tcpdump, a widely used tool for monitoring and analyzing network traffic. By sending specially crafted network packets or providing a malicious capture file, an attacker can cause the application to crash or potentially execute unauthorized code. This could lead to a complete system takeover or a disruption of network monitoring capabilities.
Technical details
A buffer overflow vulnerability exists in the GeoNetworking parser of tcpdump versions prior to 4.9.0, specifically within multiple functions in print-geonet.c. The flaw is triggered when the application attempts to parse maliciously crafted GeoNetworking packets. An attacker can exploit this by sending specially crafted packets over the network to a system running tcpdump in live capture mode or by tricking a user into opening a malicious pcap file. Successful exploitation can lead to a denial of service (application crash) or arbitrary code execution with the privileges of the tcpdump process. The issue was addressed in version 4.9.0.
Affected products
- tcpdump tcpdump before 4.9.0
Timeline
- 2017-01-27: advisory: NVD published date
- 2017-01-29: patched: Debian released security update DSA-3775-1 with version 4.9.0-1