tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet loss or segmentation fault) via a crafted Ad hoc On-Demand Distance Vector (AODV) packet, which triggers an out-of-bounds memory access.
2014-11-20T17:50:06.897
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.4 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:P
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | tcpdump | 3.8.0 | Yes |
Application | redhat | tcpdump | 3.8.2 | Yes |
Application | redhat | tcpdump | 3.9.2 | Yes |
Application | redhat | tcpdump | 3.9.3 | Yes |
Application | redhat | tcpdump | 3.9.4 | Yes |
Application | redhat | tcpdump | 3.9.5 | Yes |
Application | redhat | tcpdump | 3.9.6 | Yes |
Application | redhat | tcpdump | 3.9.7 | Yes |
Application | redhat | tcpdump | 3.9.8 | Yes |
Application | redhat | tcpdump | 4.0.0 | Yes |
Application | redhat | tcpdump | 4.1.0 | Yes |
Application | redhat | tcpdump | 4.1.1 | Yes |
Application | redhat | tcpdump | 4.1.2 | Yes |
Application | redhat | tcpdump | 4.2.1 | Yes |
Application | redhat | tcpdump | 4.3.0 | Yes |
Application | redhat | tcpdump | 4.3.1 | Yes |
Application | redhat | tcpdump | 4.4.0 | Yes |
Application | redhat | tcpdump | 4.5.0 | Yes |
Application | redhat | tcpdump | 4.5.1 | Yes |
Application | redhat | tcpdump | 4.5.2 | Yes |
Application | redhat | tcpdump | 4.6.0 | Yes |
Application | redhat | tcpdump | 4.6.1 | Yes |
Application | redhat | tcpdump | 4.6.2 | Yes |