CVE-2018-16452: High severity Apple macOS Catalina vulnerability
Last updated 25 August 2025
Other sources
tcpdump. Multiple issues were addressed by updating to tcpdump version 4.9.3 and libpcap version 1.9.1
The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smbfdata() via recursion.
— Launchpad
Credit
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8837
- CVE-2019-8853
- CVE-2019-8856
- CVE-2019-8848
- CVE-2019-8834
- CVE-2019-8842
- CVE-2019-8839
- CVE-2019-8830
- CVE-2019-8851
- CVE-2019-8833
- CVE-2019-8828
- CVE-2019-8838
- CVE-2019-8847
- CVE-2019-8852
- CVE-2019-15903
- CVE-2020-9782
- CVE-2012-1164
- CVE-2012-2668
- CVE-2013-4449
- CVE-2015-1545
- CVE-2019-13057
- CVE-2019-13565
- CVE-2019-8832
- CVE-2017-16808
- CVE-2018-10103
- CVE-2018-10105
- CVE-2018-14461
- CVE-2018-14462
- CVE-2018-14463
- CVE-2018-14464
- CVE-2018-14465
- CVE-2018-14466
- CVE-2018-14467
- CVE-2018-14468
- CVE-2018-14469
- CVE-2018-14470
- CVE-2018-14879
- CVE-2018-14880
- CVE-2018-14881
- CVE-2018-14882
- CVE-2018-16227
- CVE-2018-16228
- CVE-2018-16229
- CVE-2018-16230
- CVE-2018-16300
- CVE-2018-16301
- CVE-2018-16451
- CVE-2018-16452
- CVE-2019-15166
- CVE-2019-15167
- CVE-2019-15126
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-16452.
What is the title of the vulnerability?
The title of the vulnerability is 'The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.'
What is the impacted software?
The impacted software is tcpdump.
How can I fix this vulnerability?
You can fix this vulnerability by updating to tcpdump version 4.9.3 or later.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [GitHub Commit](https://github.com/the-tcpdump-group/tcpdump/commit/24182d959f661327525a20d9a94c98a8ec016778), [GitHub Changes](https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2019/10/msg00015.html).