CVE-2014-8768
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 20%
from disclosure to weapon4 days
Published on NVDNov 20
1st PoC+4d
exploitation probability
20%top 3% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/129156/tcpdump-4.6.2-Geonet-Denial-Of-Service.htmlunverifiedcve_referencewww.exploit-db.com/exploits/35359unverifiedexploitdbwww.exploit-db.com/exploits/35359unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-updates/2015-02/msg00062.htmlhttp://packetstormsecurity.com/files/129156/tcpdump-4.6.2-Geonet-Denial-Of-Service.htmlhttp://seclists.org/fulldisclosure/2014/Nov/48https://exchange.xforce.ibmcloud.com/vulnerabilities/98766http://www.exploit-db.com/exploits/35359http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.securityfocus.com/archive/1/534010/100/0/threadedhttp://www.securityfocus.com/bid/71155http://www.ubuntu.com/usn/USN-2433-1