Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-3798

78
FAUCET Score

CVE-2007-3798 describes a critical integer overflow vulnerability in the BGP dissector of tcpdump versions 3.9.6 and earlier, impacting various distributions including Apple, Canonical, Debian, FreeBSD, and Slackware. This flaw allows remote attackers to execute arbitrary code by sending specially crafted BGP packets, leveraging an unchecked return value. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an exploit (EDB-30319) exists on ExploitDB, and the CVE has garnered significant community discussion, indicating awareness despite no reported active exploitation or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.9.6CPE matchmatch criteria
cpe:2.3:a:tcpdump:tcpdump:*:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
6.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*
7.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*
3.1CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
70.39%
Probability of exploitation in next 30 days
EPSS Percentile
99.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-30319 · Mar 1, 2007
This CVE's current EPSS score of 0.7039 is in the 98th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: tcpdump-14:3.8.2-12.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: tcpdump-14:3.9.4-11.el5
View patch

Vendor Advisories (1)

redhatCVE-2007-3798Low

tcpdump BGP integer overflow

Jul 10, 2007

References

bugs.gentoo.org / show_bug.cgi
Third Party Advisory
cvs.tcpdump.org / cgi-bin/cvsweb/tcpdump/print-bgp.c
Broken Link
docs.info.apple.com / article.html
Broken Link
lists.apple.com / archives/security-announce/2007/Dec/msg00002.html
Mailing List
secunia.com / advisories/26135
Broken LinkVendor Advisory
secunia.com / advisories/26168
Broken LinkVendor Advisory
secunia.com / advisories/26223
Broken LinkVendor Advisory
secunia.com / advisories/26231
Broken LinkVendor Advisory
secunia.com / advisories/26263
Broken LinkVendor Advisory
secunia.com / advisories/26266
Broken LinkVendor Advisory
secunia.com / advisories/26286
Broken LinkVendor Advisory
secunia.com / advisories/26395
Broken LinkVendor Advisory
secunia.com / advisories/26404
Broken LinkVendor Advisory
secunia.com / advisories/26521
Broken LinkVendor Advisory
secunia.com / advisories/27580
Broken LinkVendor Advisory
secunia.com / advisories/28136
Broken LinkVendor Advisory
security.freebsd.org / advisories/FreeBSD-SA-07:06.tcpdump.asc
Third Party Advisory
security.gentoo.org / glsa/glsa-200707-14.xml
Third Party Advisory
slackware.com / security/viewer.php
Mailing ListPatch
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9771
Broken Link
debian.org / security/2007/dsa-1353
Third Party Advisory
digit-labs.org / files/exploits/private/tcpdump-bgp.c
Exploit
mandriva.com / security/advisories
Third Party Advisory
novell.com / linux/security/advisories/2007_16_sr.html
Broken Link
redhat.com / support/errata/RHSA-2007-0368.html
Broken Link
redhat.com / support/errata/RHSA-2007-0387.html
Broken LinkVendor Advisory
securityfocus.com / archive/1/474225/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/24965
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
trustix.org / errata/2007/0023
Broken Link
turbolinux.com / security/2007/TLSA-2007-46.txt
Broken Link
ubuntu.com / usn/usn-492-1
Third Party Advisory
us-cert.gov / cas/techalerts/TA07-352A.html
Broken LinkThird Party AdvisoryUS Government Resource
vupen.com / english/advisories/2007/2578
Broken LinkVendor Advisory
vupen.com / english/advisories/2007/4238
Broken LinkVendor Advisory