CVE-2018-14882

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-14882
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-14882.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-14882
Downstream
Related
Published
2019-10-03T16:15:12Z
Modified
2025-09-19T09:25:02.887025Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.

References

Affected packages

Alpine:v3.10

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.11

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.12

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.13

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.14

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.15

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.16

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.17

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.18

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.19

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.20

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.21

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.22

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Alpine:v3.9

tcpdump

Package

Name
tcpdump
Purl
pkg:apk/alpine/tcpdump?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.3-r0

Affected versions

4.*

4.0.0-r1
4.0.0-r2
4.1.1-r0
4.1.1-r1
4.1.1-r2
4.2.1-r0
4.3.0-r0
4.4.0-r0
4.5.1-r0
4.6.1-r0
4.6.2-r0
4.7.3-r0
4.7.4-r0
4.7.4-r1
4.7.4-r2
4.9.0-r0
4.9.0-r1
4.9.1-r0
4.9.2-r0
4.9.2-r1
4.9.2-r2
4.9.2-r3
4.9.2-r4

Git

github.com/the-tcpdump-group/tcpdump

Affected ranges

Type
GIT
Repo
https://github.com/the-tcpdump-group/tcpdump
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

tcpdump-3.*

tcpdump-3.5.1
tcpdump-3.6.1
tcpdump-3.7.1
tcpdump-3.8-bp

tcpdump-4.*

tcpdump-4.5.0
tcpdump-4.6.0
tcpdump-4.6.0-bp
tcpdump-4.7.0-bp
tcpdump-4.9.0
tcpdump-4.9.0-bp
tcpdump-4.9.1
tcpdump-4.9.2

Database specific

{
    "vanir_signatures": [
        {
            "id": "CVE-2018-14882-0b5db90e",
            "signature_type": "Function",
            "digest": {
                "function_hash": "182188482465921195765311260655303643052",
                "length": 989.0
            },
            "target": {
                "file": "print-icmp6.c",
                "function": "rpl_dao_print"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d7505276842e85bfd067fa21cdb32b8a2dc3c5e4"
        },
        {
            "id": "CVE-2018-14882-11cc68d1",
            "signature_type": "Function",
            "digest": {
                "function_hash": "226516029418000407421859892450386155559",
                "length": 4171.0
            },
            "target": {
                "file": "print-icmp6.c",
                "function": "icmp6_opt_print"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d7505276842e85bfd067fa21cdb32b8a2dc3c5e4"
        },
        {
            "id": "CVE-2018-14882-1b0f9e17",
            "signature_type": "Function",
            "digest": {
                "function_hash": "130846737505748072638949886387920379300",
                "length": 938.0
            },
            "target": {
                "file": "print-icmp6.c",
                "function": "rpl_daoack_print"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d7505276842e85bfd067fa21cdb32b8a2dc3c5e4"
        },
        {
            "id": "CVE-2018-14882-2036f55a",
            "signature_type": "Function",
            "digest": {
                "function_hash": "32872990533794806309066565516793656282",
                "length": 1089.0
            },
            "target": {
                "file": "print-icmp6.c",
                "function": "rpl_print"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d7505276842e85bfd067fa21cdb32b8a2dc3c5e4"
        },
        {
            "id": "CVE-2018-14882-28048575",
            "signature_type": "Function",
            "digest": {
                "function_hash": "16931470223185933719858487569155167747",
                "length": 980.0
            },
            "target": {
                "file": "print-icmp6.c",
                "function": "rpl_dio_printopt"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d7505276842e85bfd067fa21cdb32b8a2dc3c5e4"
        },
        {
            "id": "CVE-2018-14882-35355244",
            "signature_type": "Function",
            "digest": {
                "function_hash": "324185980701609233974044426392349376000",
                "length": 8182.0
            },
            "target": {
                "file": "print-icmp6.c",
                "function": "icmp6_print"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d7505276842e85bfd067fa21cdb32b8a2dc3c5e4"
        },
        {
            "id": "CVE-2018-14882-8020f85c",
            "signature_type": "Function",
            "digest": {
                "function_hash": "167311307617587043906639766428214462495",
                "length": 5978.0
            },
            "target": {
                "file": "print-icmp6.c",
                "function": "icmp6_nodeinfo_print"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d7505276842e85bfd067fa21cdb32b8a2dc3c5e4"
        },
        {
            "id": "CVE-2018-14882-91330036",
            "signature_type": "Function",
            "digest": {
                "function_hash": "298924858670819233079333400831601652600",
                "length": 3786.0
            },
            "target": {
                "file": "print-icmp6.c",
                "function": "icmp6_rrenum_print"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d7505276842e85bfd067fa21cdb32b8a2dc3c5e4"
        },
        {
            "id": "CVE-2018-14882-a8ac820b",
            "signature_type": "Function",
            "digest": {
                "function_hash": "88272053649363463663267635327876984712",
                "length": 728.0
            },
            "target": {
                "file": "print-icmp6.c",
                "function": "rpl_dio_print"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d7505276842e85bfd067fa21cdb32b8a2dc3c5e4"
        },
        {
            "id": "CVE-2018-14882-bd9b0b87",
            "signature_type": "Function",
            "digest": {
                "function_hash": "195455120169647778410288094622369162642",
                "length": 1755.0
            },
            "target": {
                "file": "print-icmp6.c",
                "function": "mldv2_query_print"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d7505276842e85bfd067fa21cdb32b8a2dc3c5e4"
        },
        {
            "id": "CVE-2018-14882-d8300a67",
            "signature_type": "Line",
            "digest": {
                "line_hashes": [
                    "181003773886613242633239330827373033560",
                    "34772748035413935886766294097135787174",
                    "188125337684486375574999985615886553743",
                    "51633269631643581108373943912056521989",
                    "23997182226332695483952707193067745384",
                    "6294505578454369197964859010692413719",
                    "175423479865583979879063504058917561677",
                    "224086307075555372313975829201033283042",
                    "153695385578389199877267390057813854039",
                    "223494008958646063360388168188220532452",
                    "225136894138738136494980442241196588476",
                    "224086307075555372313975829201033283042",
                    "153695385578389199877267390057813854039",
                    "223494008958646063360388168188220532452",
                    "225136894138738136494980442241196588476",
                    "224086307075555372313975829201033283042",
                    "153695385578389199877267390057813854039",
                    "330496612202949340200162624249978411527",
                    "199495615937771654298188777972231474649",
                    "179344652606165579338591740123749904665",
                    "166386760205601907137951405018266575684",
                    "81634505784373794034376891142592177678",
                    "144695167812167622251731559455764452328",
                    "24255681628569697541513881654247368588",
                    "1025200079388556488260872440879879207",
                    "4392822968583003502279588592030646380",
                    "302185276890561007937131042339425419469",
                    "324204246158391229774159757490147736560",
                    "99574785699762335165674804305487601996",
                    "43278986276141828947302435142340207912",
                    "13068543087874225218518633594557821485",
                    "4229623487846631800671166611887564485",
                    "124875215930883560392479593306451881867",
                    "40645966984482148319999260077120762266",
                    "217743082801211116011240997943976732872",
                    "96239856422616549943532252616617926837",
                    "34367508466398376531218123283335503224",
                    "260130235148047643055706416246360655239",
                    "115322680884883973618479579542987945142",
                    "37211456055567376507732057313140871330",
                    "279595294992180459962039504603254422133",
                    "260130235148047643055706416246360655239",
                    "115322680884883973618479579542987945142",
                    "37211456055567376507732057313140871330",
                    "34367508466398376531218123283335503224",
                    "99574785699762335165674804305487601996",
                    "168955833715085616409925749131045420878",
                    "128475678614245918392394164139174919624",
                    "34367508466398376531218123283335503224",
                    "99574785699762335165674804305487601996"
                ],
                "threshold": 0.9
            },
            "target": {
                "file": "print-icmp6.c"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d7505276842e85bfd067fa21cdb32b8a2dc3c5e4"
        },
        {
            "id": "CVE-2018-14882-edbfd899",
            "signature_type": "Function",
            "digest": {
                "function_hash": "196518354447424664480157491818327359090",
                "length": 1508.0
            },
            "target": {
                "file": "print-icmp6.c",
                "function": "mldv2_report_print"
            },
            "deprecated": false,
            "signature_version": "v1",
            "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d7505276842e85bfd067fa21cdb32b8a2dc3c5e4"
        }
    ]
}