vendor:
tcpdump
by:
7.5
CVSS
HIGH
Heap-based Out-of-Bounds Read
CWE
Product Name: tcpdump
Affected Version From: tcpdump version 4.10.0-PRE-GIT
Affected Version To: tcpdump version 4.10.0-PRE-GIT
Patch Exists:
Related CWE:
CPE: tcpdump/./extract.h:98:26
Platforms Tested:
Heap-based Out-of-Bounds Read in tcpdump
Through fuzzing of network capture .pcap files, we have identified 16 crashes with unique stack traces in tcpdump. These crashes are caused by heap-based out-of-bounds memory reads. The crashes can be reproduced with the latest tcpdump source code from GitHub, compiled with AddressSanitizer.