OSV-2024-393

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/pcapplusplus/OSV-2024-393.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2024-393
Published
2024-04-30T00:15:10.223298Z
Modified
2025-10-22T18:24:01.160234Z
Summary
Heap-buffer-overflow in pcpp::BgpLayer::getHeaderLen
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=67346

Crash type: Heap-buffer-overflow READ 2
Crash state:
pcpp::BgpLayer::getHeaderLen
pcpp::Packet::shortenLayer
pcpp::BgpUpdateMessageLayer::setPathAttributes
References

Affected packages

OSS-Fuzz / pcapplusplus

Package

Name
pcapplusplus
Purl
pkg:generic/pcapplusplus

Affected ranges

Type
GIT
Repo
https://github.com/seladb/PcapPlusPlus
Events

Affected versions

v24.*

v24.09

v25.*

v25.05

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

introduced_range

"3227ad11ec457c3dad062db548432d2a1c837d50:0c95dfb3557644acc6a10060e48cfae1a61fc2f0"

fixed_range

"1475cef39abf9fe61ca13c216cc374e3d5d16b59:0ae53899289fd4243fe66b9e337cc38074780664"