
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability CVE-2020-8037 affects tcpdump version 4.9.3. The issue was discovered in the ppp decapsulator component, which can be convinced to allocate a large amount of memory. This vulnerability was disclosed in November 2020 (NVD).
The vulnerability exists in the ppp decapsulator component of tcpdump where the buffer allocation doesn't properly account for captured data size. The buffer was being allocated based on the entire on-the-network packet size rather than just the captured portion, leading to excessive memory allocation. This was fixed by modifying the allocation to only account for the actual captured data size (GitHub Commit).
When exploited, this vulnerability can lead to a denial of service condition by causing the application to allocate excessive amounts of memory (Apple Security).
The issue has been patched in various distributions and versions. Ubuntu has released fixes for versions 20.04 LTS (focal), 18.04 LTS (bionic), and 16.04 LTS (xenial). Fedora has released updates for versions 32 (tcpdump-4.9.3-4.fc32) and 33 (tcpdump-4.9.3-5.fc33). Apple has included fixes in Security Update 2021-002 Catalina (Fedora Update, Debian Update).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."