Tcpdump · Tcpdump · CVE-2019-15167
**Name of the Vulnerable Software and Affected Versions**
tcpdump versions prior to 4.9.3
**Description**
The issue concerns a buffer over-read in the VRRP parser for VRRP version 3, which occurs in the `vrrp print()` function in `print-vrrp.c`. Additionally, there is a heap-based buffer over-read related to `aoe print` in `print-aoe.c` and `lookup emem` in `addrtoname.c`.
**Recommendations**
For versions prior to 4.9.3, update to version 4.9.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the VRRP parser and `aoe print` function until a patch is available.