CVE-2018-16300: High severity Apple macOS Catalina vulnerability
Last updated 25 August 2025
Other sources
tcpdump. Multiple issues were addressed by updating to tcpdump version 4.9.3 and libpcap version 1.9.1
The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgpattrprint() because of unlimited recursion.
— Launchpad
Credit
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8837
- CVE-2019-8853
- CVE-2019-8856
- CVE-2019-8848
- CVE-2019-8834
- CVE-2019-8842
- CVE-2019-8839
- CVE-2019-8830
- CVE-2019-8851
- CVE-2019-8833
- CVE-2019-8828
- CVE-2019-8838
- CVE-2019-8847
- CVE-2019-8852
- CVE-2019-15903
- CVE-2020-9782
- CVE-2012-1164
- CVE-2012-2668
- CVE-2013-4449
- CVE-2015-1545
- CVE-2019-13057
- CVE-2019-13565
- CVE-2019-8832
- CVE-2017-16808
- CVE-2018-10103
- CVE-2018-10105
- CVE-2018-14461
- CVE-2018-14462
- CVE-2018-14463
- CVE-2018-14464
- CVE-2018-14465
- CVE-2018-14466
- CVE-2018-14467
- CVE-2018-14468
- CVE-2018-14469
- CVE-2018-14470
- CVE-2018-14879
- CVE-2018-14880
- CVE-2018-14881
- CVE-2018-14882
- CVE-2018-16227
- CVE-2018-16228
- CVE-2018-16229
- CVE-2018-16230
- CVE-2018-16300
- CVE-2018-16301
- CVE-2018-16451
- CVE-2018-16452
- CVE-2019-15166
- CVE-2019-15167
- CVE-2019-15126
Frequently Asked Questions
What is CVE-2018-16300?
CVE-2018-16300 is a vulnerability in tcpdump that allows stack consumption due to unlimited recursion in the BGP parser.
How can I fix CVE-2018-16300?
To fix CVE-2018-16300, update tcpdump to version 4.9.3 or higher.
What are the affected versions of tcpdump?
The affected versions of tcpdump include 4.9.3-1~deb10u2, 4.9.3-1~deb10u1, 4.99.0-2+deb11u1, 4.99.3-1, and 4.99.4-3.
Which operating systems are affected by CVE-2018-16300?
The operating systems affected by CVE-2018-16300 include Debian, Ubuntu, Apple macOS Catalina, Apple Mojave, and Apple High Sierra.
Where can I find more information about CVE-2018-16300?
You can find more information about CVE-2018-16300 in the references provided: https://github.com/the-tcpdump-group/tcpdump/commit/af2cf04a9394c1a56227c2289ae8da262828294a, https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES, https://lists.debian.org/debian-lts-announce/2019/10/msg00015.html