CVE-2018-16300 PUBLISHED

The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.

EPSS 0.28% · 51.2th percentile

Risk Scores

EPSS Score
0.28%
51.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTStcpdump0, 4.5.1-2ubuntu1, 4.5.1-2ubuntu1.1
Ubuntu:16.04:LTStcpdump0, 4.7.4-1ubuntu1, 4.9.2-0ubuntu0.16.04.1
Ubuntu:18.04:LTStcpdump0, 4.9.2-1, 4.9.2-2

Timeline

References

Open in Interactive Console →