CVE-2018-16230 PUBLISHED

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).

EPSS 0.47% · 64.6th percentile

Risk Scores

EPSS Score
0.47%
64.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTStcpdump0, 4.7.4-1ubuntu1, 4.9.0-1ubuntu1~ubuntu16.04.1
Ubuntu:Pro:14.04:LTStcpdump4.5.1-2ubuntu1.2, 4.9.0-1ubuntu1~ubuntu14.04.1, 4.9.2-0ubuntu0.14.04.1
Ubuntu:18.04:LTStcpdump0, 4.9.2-1, 4.9.2-2

Timeline

References

Open in Interactive Console →