The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tcpdump | Tcpdump | * | 4.9.3 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | tcpdump-14:4.9.3-1.el8 | * |
Tcpdump | Ubuntu | bionic | * |
Tcpdump | Ubuntu | disco | * |
Tcpdump | Ubuntu | trusty | * |
Tcpdump | Ubuntu | trusty/esm | * |
Tcpdump | Ubuntu | upstream | * |
Tcpdump | Ubuntu | xenial | * |