Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-3798. PoCs published by mu-b.
AI-analyzed exploit summary This exploit targets an integer underflow vulnerability in tcpdump <= 3.9.6 by sending a maliciously crafted BGP UPDATE packet. The overflow occurs due to improper bounds checking in the snprintf length calculation, potentially leading to arbitrary code execution.
Description
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
Exploits (1)
This exploit targets an integer underflow vulnerability in tcpdump <= 3.9.6 by sending a maliciously crafted BGP UPDATE packet. The overflow occurs due to improper bounds checking in the snprintf length calculation, potentially leading to arbitrary code execution.
References (35)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H