PT-2019-14020 · Tcpdump+4 · Tcpdump+4

Bhargava Shastry

+1

·

Publicado

2019-09-30

·

Atualizado

2024-06-15

·

CVE-2019-15167

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions tcpdump versions prior to 4.9.3
Description The issue concerns a buffer over-read in the VRRP parser for VRRP version 3, which occurs in the vrrp print() function in print-vrrp.c. Additionally, there is a heap-based buffer over-read related to aoe print in print-aoe.c and lookup emem in addrtoname.c.
Recommendations For versions prior to 4.9.3, update to version 4.9.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the VRRP parser and aoe print function until a patch is available.

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-3120
ALT-PU-2020-3563
ALT-PU-2021-1433
CVE-2019-15167
MGASA-2019-0297
OPENSUSE-SU-2019:2344-1
OPENSUSE-SU-2019:2348-1
OPENSUSE-SU-2019_2344-1
OPENSUSE-SU-2019_2348-1
OPENSUSE-SU-2024:11425-1
SUSE-SU-2019:2674-1
SUSE-SU-2020:3360-1
USN-4252-1
USN-4252-2

Produtos afetados

Alt Linux
Ibm Aix
Suse
Ubuntu
Tcpdump