Logo
vulnerabilityCVE-2024-2397
Name
CVE-2024-2397
Source
NVD ( link)Debian ( link)
Description
Due to a bug in packet data buffers management, the PPP printer in tcpdump can enter an infinite loop when reading a crafted DLT_PPP_SERIAL .pcap savefile. This problem does not affect any tcpdump release, but it affected the git master branch from 2023-06-05 to 2024-03-21.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
tcpdump
Patched

Vulnerability Ratings#


6.2
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.99.5
Not Affected
buildroot
master
4.99.6
Not Affected
openwrt
master
4.99.6-r1
Not Affected
openwrt
openwrt-25.12
4.99.6-r1
Not Affected
yocto
master
4.99.6
Not Affected
yocto
scarthgap
4.99.4
Patched

Resolved with patches#


tcpdump (yocto:kirkstone)

#
Title
Author
Resolve
1
ppp: use the buffer stack for the de-escaping buffer.
Guy Harris <gharris@sonic.net>
CVE-2024-2397

tcpdump (yocto:scarthgap)

#
Title
Author
Resolve
1
ppp: use the buffer stack for the de-escaping buffer.
Guy Harris <gharris@sonic.net>
CVE-2024-2397