peter bassill · operator
$ cve CVE-2014-8768 JSON

CVE-2014-8768 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 19.8% (pctl 97)

Patch early

A public exploit exists.

Description

Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS19.81% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-191
On CISA KEVno
Public exploityes
Published2014-11-20
Last modified2026-06-17

Affected (4)

VendorProduct
canonicalubuntu linux
opensuseopensuse
oraclesolaris
redhattcpdump

Public exploits

SourceTitleDate
exploit-dbtcpdump 4.6.2 - Geonet Decoder Denial of Service2014-11-24

References

→ the Explorer  ·  watch your stack  ·  NVD