CVE-2015-0261: High severity tcpdump vulnerability
A flaw was found in tcpdump's IPv6 mobility printer. A remote attacker could use this flaw to cause tcpdump to crash, resulting in a denial of service, or possibly execute arbitrary code.
Upstream patch:
http://www.ca.tcpdump.org/cve/0003-test-case-for-cve2015-0261-corrupted-IPv6-mobility-h.patch
Other sources
Integer signedness error in the mobilityoptprint function in the IPv6 mobility printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) or possibly execute arbitrary code via a negative length value.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0261?
CVE-2015-0261 is classified as a high severity vulnerability that can cause denial of service and potentially allow remote code execution.
How do I fix CVE-2015-0261?
To fix CVE-2015-0261, update tcpdump to version 4.7.3 or later.
What software is affected by CVE-2015-0261?
CVE-2015-0261 affects tcpdump versions up to and including 4.7.2.
Can CVE-2015-0261 be exploited remotely?
Yes, a remote attacker can exploit CVE-2015-0261 to cause tcpdump to crash.
Is there a patch available for CVE-2015-0261?
Yes, an upstream patch has been released to address CVE-2015-0261.