CVE-2020-8037

Source
https://cve.org/CVERecord?id=CVE-2020-8037
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-8037.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-8037
Downstream
Related
Published
2020-11-04T18:15:20.843Z
Modified
2025-11-14T11:08:44.723660Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.

References

Affected packages

Git / github.com/the-tcpdump-group/tcpdump

Affected ranges

Type
GIT
Repo
https://github.com/the-tcpdump-group/tcpdump
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

tcpdump-3.*

tcpdump-3.5.1
tcpdump-3.6.1
tcpdump-3.7.1
tcpdump-3.8-bp

tcpdump-4.*

tcpdump-4.5.0
tcpdump-4.6.0
tcpdump-4.6.0-bp
tcpdump-4.7.0-bp
tcpdump-4.9.0
tcpdump-4.9.0-bp
tcpdump-4.9.1
tcpdump-4.9.2
tcpdump-4.9.3

Database specific

vanir_signatures

[
    {
        "signature_type": "Function",
        "id": "CVE-2020-8037-625654ac",
        "target": {
            "file": "print-ppp.c",
            "function": "ppp_hdlc"
        },
        "signature_version": "v1",
        "digest": {
            "function_hash": "114072365358220823879709176952693676320",
            "length": 1251.0
        },
        "deprecated": false,
        "source": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231"
    },
    {
        "signature_type": "Line",
        "id": "CVE-2020-8037-df93f99f",
        "target": {
            "file": "print-ppp.c"
        },
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "75602926860762894768813751569532021359",
                "9867738560598064159077092336868710730",
                "226286868117138916932261892023417786878",
                "312535365908525278831835037643938069206",
                "193708830256193212648148804585932547330",
                "225582233472056077528484568223799068742",
                "87512221018872648189638407990642100373",
                "331997209997900974668790162158431339155",
                "32254091627956064590784894660703272575",
                "275556175249599490980814440375788132190",
                "79058067046007865613622272898805451482",
                "96770968572884396529904239864250777959",
                "15054595184741052885796942294073694432",
                "169938687647837023712455514535228888440",
                "179516277381903108913256904174120081207",
                "188861693945644257165746229702332158795",
                "241755533398317547277580406153182923367",
                "277299685682914552613762330927893646226",
                "43450640239716668424840137206990379970",
                "169909079340584079484773553150578196492"
            ]
        },
        "deprecated": false,
        "source": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231"
    }
]

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-8037.json"