Executive brief
tcpdump is a widely used tool for monitoring and analyzing network traffic. A vulnerability in its IPv6 traffic parser allows an attacker to send specially crafted network packets that can cause the tool to crash or potentially execute unauthorized code. This could disrupt network monitoring operations or allow an attacker to gain a foothold on the system running the analysis tool.
Technical details
A buffer overflow vulnerability exists in tcpdump versions prior to 4.9.0 within the IPv6 parsing logic (print-ip6.c:ip6_print()). The flaw is triggered when the application processes specially crafted IPv6 packets. An unauthenticated remote attacker can exploit this by sending malicious packets over a network segment where tcpdump is performing live capture, or by providing a crafted pcap file for offline analysis. Successful exploitation can lead to a denial of service (application crash), an infinite loop, or potentially arbitrary code execution with the privileges of the tcpdump process. The issue was addressed in version 4.9.0.
Affected products
- tcpdump tcpdump before 4.9.0
Timeline
- 2017-01-26: advisory: Debian security release announcement for version 4.9.0-1
- 2017-01-28: disclosed: NVD publication date
- 2017-01-29: patched: Debian Security Advisory DSA-3775-1 issued