U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-8006

Change History

New CVE Received from Tcpdump Group 8/30/2024 8:15:05 PM

Action Type Old Value New Value
Added Description

								
							
							
						
Remote packet capture support is disabled by default in libpcap.  When a user builds libpcap with remote packet capture support enabled, one of the functions that become available is pcap_findalldevs_ex().  One of the function arguments can be a filesystem path, which normally means a directory with input data files.  When the specified path cannot be used as a directory, the function receives NULL from opendir(), but does not check the return value and passes the NULL value to readdir(), which causes a NULL pointer derefence.
Added CVSS V3.1

								
							
							
						
Tcpdump Group AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Added CWE

								
							
							
						
Tcpdump Group CWE-476
Added Reference

								
							
							
						
Tcpdump Group https://github.com/the-tcpdump-group/libpcap/commit/0f8a103469ce87d2b8d68c5130a46ddb7fb5eb29 [No types assigned]
Added Reference

								
							
							
						
Tcpdump Group https://github.com/the-tcpdump-group/libpcap/commit/8a633ee5b9ecd9d38a587ac9b204e2380713b0d6 [No types assigned]