CVE-2024-2397 describes a bug in tcpdump's PPP printer that can lead to an infinite loop when processing a specially crafted DLT_PPP_SERIAL .pcap savefile. This vulnerability specifically affected the tcpdump git master branch between June 5, 2023, and March 21, 2024, and does not impact any official tcpdump releases. Rated as Medium severity (CVSS 6.2), the vulnerability has a local attack vector with low complexity, requiring no user interaction or privileges. Its primary impact is high availability, as it can cause a denial of service. Currently, there is no evidence of active exploitation, nor are there any public exploit codes available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| The Tcpdump Group | Tcpdump | >= 0d4083e, < b9811efCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.