Skip to content
Snippets Groups Projects
user avatar
Hauke Mehrtens authored
This fixes the following security problem:
The command-line argument parser in tcpdump before 4.99.0 has a buffer
overflow in tcpdump.c:read_infile(). To trigger this vulnerability the
attacker needs to create a 4GB file on the local filesystem and to
specify the file name as the value of the -F command-line argument of
tcpdump.

Signed-off-by: default avatarHauke Mehrtens <hauke@hauke-m.de>
8f5875c4
History