CVE-2018-14879

HIGH

tcpdump <4.9.3 - Buffer Overflow

Title source: llm

Description

The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().

Exploits (1)

nomisec WRITEUP
by Trinadh465 · poc
https://github.com/Trinadh465/external_tcpdump_CVE-2018-14879

References (17)

Scores

CVSS v3 7.0
EPSS 0.0052
EPSS Percentile 66.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-120
Status published

Affected Products (13)

f5/traffix_signaling_delivery_controller < 5.1.0
tcpdump/tcpdump < 4.9.3
apple/mac_os_x < 10.15.2
debian/debian_linux
debian/debian_linux
debian/debian_linux
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
opensuse/leap
opensuse/leap
redhat/enterprise_linux
redhat/enterprise_linux

Timeline

Published Oct 03, 2019
Tracked Since Feb 18, 2026