PT-2019-4099 · Tcpdump+7 · Tcpdump+7

Publicado

2019-09-30

·

Atualizado

2024-06-15

·

CVE-2018-10105

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions tcpdump versions prior to 4.9.3
Description The issue is related to insufficient input validation in the tcpdump utility, which can be exploited by a remote attacker to gain unauthorized access to information and compromise its integrity and availability. The vulnerability specifically affects the handling of SMB data and is also related to a heap-based buffer over-read.
Recommendations For versions prior to 4.9.3, update to version 4.9.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the tcpdump utility to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-3120
ALT-PU-2020-3563
ALT-PU-2021-1433
BDU:2019-04667
BDU:2020-04923
CESA-2020_4760
CVE-2018-10105
DLA-1955-1
DSA-4547-1
MGASA-2019-0297
OPENSUSE-SU-2019:2344-1
OPENSUSE-SU-2019:2348-1
OPENSUSE-SU-2019_2344-1
OPENSUSE-SU-2019_2348-1
OPENSUSE-SU-2024:11425-1
RHSA-2020:4760
RHSA-2020_4760
RHSA-2021:2191
RLSA-2020:4760
SUSE-SU-2019:14191-1
SUSE-SU-2019:2674-1
SUSE-SU-2019_14191-1
SUSE-SU-2020:3360-1
USN-4252-1
USN-4252-2

Produtos afetados

Alt Linux
Centos
Ibm Aix
Red Hat
Rocky Linux
Suse
Ubuntu
Tcpdump