First published: Sat Jan 28 2017(Updated: )
The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in addrtoname.c:lookup_nsap().
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
tcpdump tcpdump | <=4.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5485 is classified as a high-severity vulnerability due to its potential for causing a buffer overflow.
To fix CVE-2017-5485, you should upgrade tcpdump to version 4.9.0 or later.
CVE-2017-5485 can lead to denial of service or arbitrary code execution due to the buffer overflow.
CVE-2017-5485 affects tcpdump versions prior to 4.9.0.
There is no known workaround for CVE-2017-5485; updating to a secure version is recommended.