CVE-2016-7939 describes a critical buffer overflow vulnerability in the GRE parser of tcpdump versions prior to 4.9.0, specifically within print-gre.c. This flaw carries a CVSS v3 score of 9.8, indicating a severe impact with high confidentiality, integrity, and availability compromise, achievable remotely without user interaction. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability has garnered significant community attention with 10 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.8.1CPE matchmatch criteria | cpe:2.3:a:tcpdump:tcpdump:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.