The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.
Metrics
Affected Vendors & Products
References
History
Sat, 05 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet. | |
| Title | OOBR in rpcap client in libpcap before 1.10.7 | |
| Weaknesses | CWE-126 CWE-1288 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Tcpdump
Published:
Updated: 2026-09-05T18:51:57.956Z
Reserved: 2026-07-29T13:32:44.322Z
Link: CVE-2026-18238
No data.
Status : Received
Published: 2026-09-05T19:16:55.477
Modified: 2026-09-05T19:16:55.477
Link: CVE-2026-18238
No data.
OpenCVE Enrichment
Updated: 2026-09-05T21:00:05Z