MGASA-2014-0503
Dashboard / Vulnerabilities / MGASA-2014-0503
Summary: Updated tcpdump package fixes security vulnerabilities
Details: The Tcpdump program could crash when processing a malformed OLSR payload when the verbose output flag was set (CVE-2014-8767). The application decoder for the Ad hoc On-Demand Distance Vector (AODV) protocol in Tcpdump fails to perform input validation and performs unsafe out-of-bound accesses. The application will usually not crash, but perform out-of-bounds accesses and output/leak larger amounts of invalid data, which might lead to dropped packets. It is unknown if a payload exists that might trigger segfaults (CVE-2014-8769).
References: https://advisories.mageia.org/MGASA-2014-0503.html, https://bugs.mageia.org/show_bug.cgi?id=14673, https://lists.fedoraproject.org/pipermail/package-announce/2014-November/144951.html
Affected packages
Package
Name: tcpdump
Purl: pkg:rpm/mageia/tcpdump?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
