← All CVEs

CVE-2014-8768

medium · 5

Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame.

5
CVSS
19.8%
EPSS (exploit prob.)
97th
EPSS percentile
2014-11-20
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-191

Affected products

VendorProductAffected versions
opensuseopensuse13.1
opensuseopensuse13.2
canonicalubuntu_linux10.04
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux14.10
oraclesolaris11.2
redhattcpdump4.5.0
redhattcpdump4.5.1
redhattcpdump4.5.2
redhattcpdump4.6.0
redhattcpdump4.6.1
redhattcpdump4.6.2
opensuseopensuse13.1
opensuseopensuse13.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-8768