Steffen Bauch discovered that tcpdump incorrectly handled printing OSLR packets. A remote attacker could use this issue to cause tcpdump to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2014-8767)
Steffen Bauch discovered that tcpdump incorrectly handled printing GeoNet packets. A remote attacker could use this issue to cause tcpdump to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2014-8768)
Steffen Bauch discovered that tcpdump incorrectly handled printing AODV packets. A remote attacker could use this issue to cause tcpdump to crash, resulting in a denial of service, reveal sensitive information, or possibly execute arbitrary code. (CVE-2014-8769)
It was discovered that tcpdump incorrectly handled printing PPP packets. A remote attacker could use this issue to cause tcpdump to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2014-9140)
In the default installation, attackers would be isolated by the tcpdump AppArmor profile.
{
"binaries": [
{
"binary_version": "4.5.1-2ubuntu1.1",
"binary_name": "tcpdump"
}
],
"availability": "No subscription required"
}
{
"ecosystem": "Ubuntu:14.04:LTS",
"cves": [
{
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
],
"id": "CVE-2014-8767"
},
{
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
],
"id": "CVE-2014-8768"
},
{
"severity": [
{
"score": "low",
"type": "Ubuntu"
}
],
"id": "CVE-2014-8769"
},
{
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2014-9140"
}
]
}