First published: Sat Jan 28 2017(Updated: )
The compressed SLIP parser in tcpdump before 4.9.0 has a buffer overflow in print-sl.c:sl_if_print().
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tcpdump | <=4.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7925 is classified as a high-severity vulnerability due to the buffer overflow risk it poses.
To fix CVE-2016-7925, update tcpdump to version 4.9.0 or later.
CVE-2016-7925 can potentially allow an attacker to execute arbitrary code on systems running vulnerable versions of tcpdump.
CVE-2016-7925 affects tcpdump versions prior to 4.9.0.
Yes, CVE-2016-7925 may be exploitable by remote attackers who can send specially crafted input to tcpdump.