CVE-2018-14879: Buffer Overflow
Last updated 24 July 2024
Other sources
tcpdump. Multiple issues were addressed by updating to tcpdump version 4.9.3 and libpcap version 1.9.1
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:getnextfile().
— Launchpad
Credit
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8837
- CVE-2019-8853
- CVE-2019-8856
- CVE-2019-8848
- CVE-2019-8834
- CVE-2019-8842
- CVE-2019-8839
- CVE-2019-8830
- CVE-2019-8851
- CVE-2019-8833
- CVE-2019-8828
- CVE-2019-8838
- CVE-2019-8847
- CVE-2019-8852
- CVE-2019-15903
- CVE-2020-9782
- CVE-2012-1164
- CVE-2012-2668
- CVE-2013-4449
- CVE-2015-1545
- CVE-2019-13057
- CVE-2019-13565
- CVE-2019-8832
- CVE-2017-16808
- CVE-2018-10103
- CVE-2018-10105
- CVE-2018-14461
- CVE-2018-14462
- CVE-2018-14463
- CVE-2018-14464
- CVE-2018-14465
- CVE-2018-14466
- CVE-2018-14467
- CVE-2018-14468
- CVE-2018-14469
- CVE-2018-14470
- CVE-2018-14879
- CVE-2018-14880
- CVE-2018-14881
- CVE-2018-14882
- CVE-2018-16227
- CVE-2018-16228
- CVE-2018-16229
- CVE-2018-16230
- CVE-2018-16300
- CVE-2018-16301
- CVE-2018-16451
- CVE-2018-16452
- CVE-2019-15166
- CVE-2019-15167
- CVE-2019-15126
Frequently Asked Questions
What is CVE-2018-14879?
CVE-2018-14879 is a vulnerability in tcpdump before version 4.9.3 that has a buffer overflow in tcpdump.c:get_next_file().
How severe is CVE-2018-14879?
CVE-2018-14879 has a severity level of 7 (high).
What software is affected by CVE-2018-14879?
The software affected by CVE-2018-14879 includes Apple macOS Catalina 10.15.2, Apple Mojave, Apple High Sierra, ubuntu/tcpdump, debian/tcpdump, Apple High Sierra 5.0.0 to 5.1.0, Tcpdump Tcpdump up to version 4.9.3, Apple Mac OS X up to version 10.15.2, Debian Debian Linux 8.0, 9.0, and 10.0, Fedoraproject Fedora 29, 30, and 31, openSUSE Leap 15.0 and 15.1, and Redhat Enterprise Linux 7.0 and 8.0.
How do I fix CVE-2018-14879 for macOS Catalina?
To fix CVE-2018-14879 on macOS Catalina, update to tcpdump version 4.9.3.
How do I fix CVE-2018-14879 for Ubuntu?
To fix CVE-2018-14879 on Ubuntu, update to tcpdump version 4.9.3-0ubuntu0.14.04.1+ or 4.9.3-0ubuntu0.16.04.1 or 4.9.3-0ubuntu0.18.04.1 or a higher version.