Junglewise Threat Intelligence

CVE-2017-5202: tcpdump buffer overflow in ISO CLNS parser

CVE-2017-5202 · Severity: critical · CVSS 9.8 · Published 2017-01-28

Technologies: Tcpdump. Vendors: Tcpdump.

Executive brief

tcpdump is a widely used command-line tool for monitoring and analyzing network traffic. A vulnerability in its ISO CLNS protocol parser allows an attacker to trigger a buffer overflow by sending specially crafted network packets. This could lead to a complete system crash or allow the attacker to gain unauthorized control over the system running the tool.

Technical details

A buffer overflow vulnerability exists in tcpdump versions prior to 4.9.0 within the ISO CLNS (Connectionless Network Service) parser. The flaw is located in the clnp_print() function in print-isoclns.c and is triggered during the processing of malformed packets. A remote, unauthenticated attacker can exploit this by sending specially crafted network traffic to a segment where tcpdump is performing live capture, or by tricking a user into opening a malicious pcap file. Successful exploitation can result in a denial of service (application crash) or potentially arbitrary code execution with the privileges of the tcpdump process. The issue was addressed in version 4.9.0.

Affected products

  • tcpdump tcpdump < 4.9.0

Timeline

  • 2017-01-26: disclosed: Vulnerability reported in Debian bug tracking system
  • 2017-01-27: advisory: NVD publication date
  • 2017-01-29: patched: Debian released security update DSA-3775-1

References