CVE-2018-16301
🟡 Monitoruj
Przepełnienie bufora w tcpdump umożliwia zdalne wykonanie kodu poprzez specjalnie przygotowany plik.
CVSS
7.8
EPSS
0.6%
Exploit
none
Vendor
tcpdump
Opis źródłowy (NVD)
The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.
buffer-overflow
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2019-10-03 16:15:12 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:16:45 UTC |