CVE-2020-8037: ppp decapsulator can be convinced to allocate a large amount of memory
Published Nov 4, 2020
·Updated
tcpdump. This issue was addressed with improved checks.
Other sources
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
Credit
an anonymous researcher, an anonymous researcher, an anonymous researcher
Affected Software
30 affected componentsFixes available
Apple macOS Big Sur<11.3
11.3
Apple Catalina
Apple Mojave
tcpdump tcpdump=4.9.3
Debian Debian Linux=9.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Apple iOS and macOS<10.14.6
Apple iOS and macOS>=10.15<10.15.7
Apple iOS and macOS=10.14.6
Apple iOS and macOS=10.14.6-security_update_2019-001
Apple iOS and macOS=10.14.6-security_update_2019-002
Apple iOS and macOS=10.14.6-security_update_2020-001
Apple iOS and macOS=10.14.6-security_update_2020-002
Apple iOS and macOS=10.14.6-security_update_2020-003
Apple iOS and macOS=10.14.6-security_update_2020-004
Apple iOS and macOS=10.14.6-security_update_2020-005
Apple iOS and macOS=10.14.6-security_update_2020-006
Apple iOS and macOS=10.14.6-security_update_2020-007
Apple iOS and macOS=10.14.6-security_update_2021-001
Apple iOS and macOS=10.15.7
Apple iOS and macOS=10.15.7-security_update_2020-001
Apple iOS and macOS=10.15.7-security_update_2021-001
Apple iOS and macOS=10.15.7-supplemental_update
Apple macOS>=11.0<11.3
F5 BIG-IP>=17.5.0<=17.5.1, >=17.1.0<=17.1.2
17.5.1.117.1.3
F5 BIG-IP>=16.1.0<=16.1.6
F5 BIG-IP>=15.1.0<=15.1.10
F5 F5OS-A=1.8.0, >=1.5.1<=1.5.2
1.5.3
F5 F5OS-C>=1.6.0<=1.6.2
1.8.0
Remediation
Event History
Nov 4, 2020
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionWeakness
Feb 24, 2025
Advisory Published
via F5·04:31 PM
Data Sourced
via F5·04:31 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-1853
- CVE-2021-1849
- CVE-2021-1867
- CVE-2021-1810
- CVE-2021-1808
- CVE-2021-1857
- CVE-2021-30752
- CVE-2021-30664
- CVE-2021-1846
- CVE-2021-1809
- CVE-2021-30659
- CVE-2021-1847
- CVE-2021-1811
- CVE-2020-8284
- CVE-2020-8286
- CVE-2020-8285
- CVE-2021-1784
- CVE-2021-1872
- CVE-2021-1881
- CVE-2021-1882
- CVE-2021-1813
- CVE-2021-1883
- CVE-2021-1884
- CVE-2021-1880
- CVE-2021-30653
- CVE-2021-1814
- CVE-2021-1843
- CVE-2021-1885
- CVE-2021-1858
- CVE-2021-30743
- CVE-2021-30658
- CVE-2021-1841
- CVE-2021-1834
- CVE-2021-1860
- CVE-2021-1840
- CVE-2021-1851
- CVE-2021-1832
- CVE-2021-30660
- CVE-2021-30652
- CVE-2021-1875
- CVE-2021-1824
- CVE-2021-1859
- CVE-2021-1876
- CVE-2021-1815
- CVE-2021-1739
- CVE-2021-1740
- CVE-2021-1861
- CVE-2021-1855
- CVE-2021-1868
- CVE-2021-30750
- CVE-2021-1878
- CVE-2021-30657
- CVE-2021-30856
- CVE-2020-8037
- CVE-2021-1839
- CVE-2021-1825
- CVE-2021-1817
- CVE-2021-1826
- CVE-2021-1820
- CVE-2021-30661
- CVE-2020-7463
- CVE-2021-1828
- CVE-2021-1829
- CVE-2021-30655
- CVE-2021-1770
- CVE-2021-1873
- CVE-2021-1797
- CVE-2020-27942
- CVE-2020-3838
- CVE-2021-1805
- CVE-2021-1806
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-8037.
2
What software versions are affected by this vulnerability?
The vulnerability affects Apple Catalina, Apple Mojave, and Apple macOS Big Sur (up to version 11.3).
3
How was this vulnerability addressed?
This vulnerability was addressed with improved checks.
4
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following references: [Reference 1](https://support.apple.com/en-us/HT212326), [Reference 2](https://support.apple.com/en-us/HT212327), and [Reference 3](https://support.apple.com/en-us/HT212325).