CVE-2018-16451: Critical severity Apple macOS Catalina vulnerability
Published Oct 3, 2019
·Updated
Last updated 25 August 2025
Other sources
tcpdump. Multiple issues were addressed by updating to tcpdump version 4.9.3 and libpcap version 1.9.1
The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:printtrans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.
— Launchpad
Credit
CVE-2017-16808, CVE-2018-10103, CVE-2018-10105, CVE-2018-14461, CVE-2018-14462, CVE-2018-14463, CVE-2018-14464, CVE-2018-14465, CVE-2018-14466, CVE-2018-14467, CVE-2018-14468, CVE-2018-14469, CVE-2018-14470, CVE-2018-14879, CVE-2018-14880, CVE-2018-14881, CVE-2018-14882, CVE-2018-16227, CVE-2018-16228, CVE-2018-16229, CVE-2018-16230, CVE-2018-16300, CVE-2018-16301, CVE-2018-16451, CVE-2018-16452, CVE-2019-15166, CVE-2019-15167
Affected Software
16 affected componentsFixes available
Apple macOS Catalina<10.15.2
10.15.2
Apple Mojave
Apple High Sierra
tcpdump tcpdump<4.9.3
Apple iOS and macOS<10.15.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=29
Fedoraproject Fedora=30
Fedoraproject Fedora=31
openSUSE Leap=15.0
openSUSE Leap=15.1
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
debian/tcpdump
4.99.0-2+deb11u14.99.3-14.99.5-24.99.6-2
Remediation
Event History
Oct 3, 2019
CVE Published
via MITRE·03:57 PM
Data Sourced
via MITRE·03:57 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 4, 2025
Data Sourced
via Ubuntu·06:59 PM
RemedyDescriptionSeverityAffected Software
Feb 19, 2026
Data Sourced
via Launchpad·09:49 PM
Description
Mar 8, 2026
Data Sourced
via Debian·10:03 PM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8837
- CVE-2019-8853
- CVE-2019-8856
- CVE-2019-8848
- CVE-2019-8834
- CVE-2019-8842
- CVE-2019-8839
- CVE-2019-8830
- CVE-2019-8851
- CVE-2019-8833
- CVE-2019-8828
- CVE-2019-8838
- CVE-2019-8847
- CVE-2019-8852
- CVE-2019-15903
- CVE-2020-9782
- CVE-2012-1164
- CVE-2012-2668
- CVE-2013-4449
- CVE-2015-1545
- CVE-2019-13057
- CVE-2019-13565
- CVE-2019-8832
- CVE-2017-16808
- CVE-2018-10103
- CVE-2018-10105
- CVE-2018-14461
- CVE-2018-14462
- CVE-2018-14463
- CVE-2018-14464
- CVE-2018-14465
- CVE-2018-14466
- CVE-2018-14467
- CVE-2018-14468
- CVE-2018-14469
- CVE-2018-14470
- CVE-2018-14879
- CVE-2018-14880
- CVE-2018-14881
- CVE-2018-14882
- CVE-2018-16227
- CVE-2018-16228
- CVE-2018-16229
- CVE-2018-16230
- CVE-2018-16300
- CVE-2018-16301
- CVE-2018-16451
- CVE-2018-16452
- CVE-2019-15166
- CVE-2019-15167
- CVE-2019-15126
Frequently Asked Questions
1
What is CVE-2018-16451?
CVE-2018-16451 is a vulnerability in tcpdump that allows buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.
2
What is the severity of CVE-2018-16451?
The severity of CVE-2018-16451 is not specified in the information provided.
3
How can I fix CVE-2018-16451?
To fix CVE-2018-16451, update tcpdump to version 4.9.3 or later.
4
Where can I find more information about CVE-2018-16451?
You can find more information about CVE-2018-16451 at the following references: [1] [2] [3].
5
Which software versions are affected by CVE-2018-16451?
tcpdump versions before 4.9.3 are affected by CVE-2018-16451.