USN-3415-1

    Dashboard / Vulnerabilities / USN-3415-1

    USN-3415-1

    Published: 14 Sept 2017Last Modified: 10 Feb 2026

    Summary: tcpdump vulnerabilities

    Details: Wilfried Kirsch discovered a buffer overflow in the SLIP decoder in tcpdump. A remote attacker could use this to cause a denial of service (application crash) or possibly execute arbitrary code. (CVE-2017-11543) Bhargava Shastry discovered a buffer overflow in the bitfield converter utility function bittok2str_internal() in tcpdump. A remote attacker could use this to cause a denial of service (application crash) or possibly execute arbitrary code. (CVE-2017-13011) Otto Airamo and Antti Levomäki discovered logic errors in different protocol parsers in tcpdump that could lead to an infinite loop. A remote attacker could use these to cause a denial of service (application hang). CVE-2017-12989, CVE-2017-12990, CVE-2017-12995, CVE-2017-12997) Otto Airamo, Brian Carpenter, Yannick Formaggio, Kamil Frankowicz, Katie Holly, Kim Gwan Yeong, Antti Levomäki, Henri Salo, and Bhargava Shastry discovered out-of-bounds reads in muliptle protocol parsers in tcpdump. A remote attacker could use these to cause a denial of service (application crash). (CVE-2017-11108, CVE-2017-11541, CVE-2017-11542, CVE-2017-12893, CVE-2017-12894, CVE-2017-12895, CVE-2017-12896, CVE-2017-12897, CVE-2017-12898, CVE-2017-12899, CVE-2017-12900, CVE-2017-12901, CVE-2017-12902, CVE-2017-12985, CVE-2017-12986, CVE-2017-12987, CVE-2017-12988, CVE-2017-12991, CVE-2017-12992, CVE-2017-12993, CVE-2017-12994, CVE-2017-12996, CVE-2017-12998, CVE-2017-12999, CVE-2017-13000, CVE-2017-13001, CVE-2017-13002, CVE-2017-13003, CVE-2017-13004, CVE-2017-13005, CVE-2017-13006, CVE-2017-13007, CVE-2017-13008, CVE-2017-13009, CVE-2017-13010, CVE-2017-13012, CVE-2017-13013, CVE-2017-13014, CVE-2017-13015, CVE-2017-13016, CVE-2017-13017, CVE-2017-13018, CVE-2017-13019, CVE-2017-13020, CVE-2017-13021, CVE-2017-13022, CVE-2017-13023, CVE-2017-13024, CVE-2017-13025, CVE-2017-13026, CVE-2017-13027, CVE-2017-13028, CVE-2017-13029, CVE-2017-13030, CVE-2017-13031, CVE-2017-13032, CVE-2017-13033, CVE-2017-13034, CVE-2017-13035, CVE-2017-13036, CVE-2017-13037, CVE-2017-13038, CVE-2017-13039, CVE-2017-13040, CVE-2017-13041, CVE-2017-13042, CVE-2017-13043, CVE-2017-13044, CVE-2017-13045, CVE-2017-13046, CVE-2017-13047, CVE-2017-13048, CVE-2017-13049, CVE-2017-13050, CVE-2017-13051, CVE-2017-13052, CVE-2017-13053, CVE-2017-13054, CVE-2017-13055, CVE-2017-13687, CVE-2017-13688, CVE-2017-13689, CVE-2017-13690, CVE-2017-13725)

    References: https://ubuntu.com/security/notices/USN-3415-1, https://ubuntu.com/security/CVE-2017-11108, https://ubuntu.com/security/CVE-2017-11541, https://ubuntu.com/security/CVE-2017-11542, https://ubuntu.com/security/CVE-2017-11543, https://ubuntu.com/security/CVE-2017-12893, https://ubuntu.com/security/CVE-2017-12894, https://ubuntu.com/security/CVE-2017-12895, https://ubuntu.com/security/CVE-2017-12896, https://ubuntu.com/security/CVE-2017-12897, https://ubuntu.com/security/CVE-2017-12898, https://ubuntu.com/security/CVE-2017-12899, https://ubuntu.com/security/CVE-2017-12900, https://ubuntu.com/security/CVE-2017-12901, https://ubuntu.com/security/CVE-2017-12902, https://ubuntu.com/security/CVE-2017-12985, https://ubuntu.com/security/CVE-2017-12986, https://ubuntu.com/security/CVE-2017-12987, https://ubuntu.com/security/CVE-2017-12988, https://ubuntu.com/security/CVE-2017-12989, https://ubuntu.com/security/CVE-2017-12990, https://ubuntu.com/security/CVE-2017-12991, https://ubuntu.com/security/CVE-2017-12992, https://ubuntu.com/security/CVE-2017-12993, https://ubuntu.com/security/CVE-2017-12994, https://ubuntu.com/security/CVE-2017-12995, https://ubuntu.com/security/CVE-2017-12996, https://ubuntu.com/security/CVE-2017-12997, https://ubuntu.com/security/CVE-2017-12998, https://ubuntu.com/security/CVE-2017-12999, https://ubuntu.com/security/CVE-2017-13000, https://ubuntu.com/security/CVE-2017-13001, https://ubuntu.com/security/CVE-2017-13002, https://ubuntu.com/security/CVE-2017-13003, https://ubuntu.com/security/CVE-2017-13004, https://ubuntu.com/security/CVE-2017-13005, https://ubuntu.com/security/CVE-2017-13006, https://ubuntu.com/security/CVE-2017-13007, https://ubuntu.com/security/CVE-2017-13008, https://ubuntu.com/security/CVE-2017-13009, https://ubuntu.com/security/CVE-2017-13010, https://ubuntu.com/security/CVE-2017-13011, https://ubuntu.com/security/CVE-2017-13012, https://ubuntu.com/security/CVE-2017-13013, https://ubuntu.com/security/CVE-2017-13014, https://ubuntu.com/security/CVE-2017-13015, https://ubuntu.com/security/CVE-2017-13016, https://ubuntu.com/security/CVE-2017-13017, https://ubuntu.com/security/CVE-2017-13018, https://ubuntu.com/security/CVE-2017-13019, https://ubuntu.com/security/CVE-2017-13020, https://ubuntu.com/security/CVE-2017-13021, https://ubuntu.com/security/CVE-2017-13022, https://ubuntu.com/security/CVE-2017-13023, https://ubuntu.com/security/CVE-2017-13024, https://ubuntu.com/security/CVE-2017-13025, https://ubuntu.com/security/CVE-2017-13026, https://ubuntu.com/security/CVE-2017-13027, https://ubuntu.com/security/CVE-2017-13028, https://ubuntu.com/security/CVE-2017-13029, https://ubuntu.com/security/CVE-2017-13030, https://ubuntu.com/security/CVE-2017-13031, https://ubuntu.com/security/CVE-2017-13032, https://ubuntu.com/security/CVE-2017-13033, https://ubuntu.com/security/CVE-2017-13034, https://ubuntu.com/security/CVE-2017-13035, https://ubuntu.com/security/CVE-2017-13036, https://ubuntu.com/security/CVE-2017-13037, https://ubuntu.com/security/CVE-2017-13038, https://ubuntu.com/security/CVE-2017-13039, https://ubuntu.com/security/CVE-2017-13040, https://ubuntu.com/security/CVE-2017-13041, https://ubuntu.com/security/CVE-2017-13042, https://ubuntu.com/security/CVE-2017-13043, https://ubuntu.com/security/CVE-2017-13044, https://ubuntu.com/security/CVE-2017-13045, https://ubuntu.com/security/CVE-2017-13046, https://ubuntu.com/security/CVE-2017-13047, https://ubuntu.com/security/CVE-2017-13048, https://ubuntu.com/security/CVE-2017-13049, https://ubuntu.com/security/CVE-2017-13050, https://ubuntu.com/security/CVE-2017-13051, https://ubuntu.com/security/CVE-2017-13052, https://ubuntu.com/security/CVE-2017-13053, https://ubuntu.com/security/CVE-2017-13054, https://ubuntu.com/security/CVE-2017-13055, https://ubuntu.com/security/CVE-2017-13687, https://ubuntu.com/security/CVE-2017-13688, https://ubuntu.com/security/CVE-2017-13689, https://ubuntu.com/security/CVE-2017-13690, https://ubuntu.com/security/CVE-2017-13725

    Affected packages

    Package

    Name: tcpdump

    Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.9.2-0ubuntu0.14.04.1

    Affected versions

    4.4.0-1ubuntu1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High