CVE-2014-8769

medium
Published 2014-11-20 · Modified 2026-05-06
CVSS v3
VIR risk
6.4

Description

tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet loss or segmentation fault) via a crafted Ad hoc On-Demand Distance Vector (AODV) packet, which triggers an out-of-bounds memory access.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4.6.2-2
debian debianbullseyefixed4.6.2-2
debian debianforkyfixed4.6.2-2
debian debiansidfixed4.6.2-2
debian debiantrixiefixed4.6.2-2

Application impact

VendorProductVersionsFixed
redhat redhattcpdump3.8.0
redhat redhattcpdump3.8.2
redhat redhattcpdump3.9.2
redhat redhattcpdump3.9.3
redhat redhattcpdump3.9.4
redhat redhattcpdump3.9.5
redhat redhattcpdump3.9.6
redhat redhattcpdump3.9.7
redhat redhattcpdump3.9.8
redhat redhattcpdump4.0.0
redhat redhattcpdump4.1.0
redhat redhattcpdump4.1.1
redhat redhattcpdump4.1.2
redhat redhattcpdump4.2.1
redhat redhattcpdump4.3.0
redhat redhattcpdump4.3.1
redhat redhattcpdump4.4.0
redhat redhattcpdump4.5.0
redhat redhattcpdump4.5.1
redhat redhattcpdump4.5.2
redhat redhattcpdump4.6.0
redhat redhattcpdump4.6.1
redhat redhattcpdump4.6.2

References

CWEs

CWE-119

💬 Discuss CVE-2014-8769 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.