CVE-2014-8768
MEDIUM 5.0EPSS 19.8%
Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P - EPSS
- 19.81% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2014-11-20
- Updated
- 2024-08-06
Proof-of-concept exploits (4)
- http://packetstormsecurity.com/files/129156/tcpdump-4.6.2-Geonet-Denial-Of-Service.html
- http://www.exploit-db.com/exploits/35359
- http://seclists.org/fulldisclosure/2014/Nov/48
- http://www.securityfocus.com/archive/1/534010/100/0/threaded