CVE-2020-8037

HIGH

tcpdump 4.9.3 - Memory Corruption

Title source: llm
STIX 2.1

Description

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.

References (8)

Core 8
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Apr/51
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212325
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212326
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212327

Scores

CVSS v3 7.5
EPSS 0.0027
EPSS Percentile 50.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (8)
apple/mac_os_x 10.14.6 (11 CPE variants)
apple/mac_os_x 10.15.7 (4 CPE variants)
apple/mac_os_x < 10.14.6
apple/macos 11.0 - 11.3
debian/debian_linux 9.0
fedoraproject/fedora 32
fedoraproject/fedora 33
tcpdump/tcpdump 4.9.3
Published Nov 04, 2020
Tracked Since Feb 18, 2026