CVE-2017-11108 PUBLISHED

tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.

EPSS 1.94% · 83.3th percentile

Risk Scores

EPSS Score
1.94%
83.3th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTStcpdump0, 4.4.0-1ubuntu1, 4.5.1-2ubuntu1
Ubuntu:16.04:LTStcpdump0, 4.7.4-1ubuntu1, 4.9.0-1ubuntu1~ubuntu16.04.1

Timeline

References

Open in Interactive Console →