SUSE-SU-2017:2690-1
Dashboard / Vulnerabilities / SUSE-SU-2017:2690-1
SUSE-SU-2017:2690-1
Summary: Security update for tcpdump
Details: This update for tcpdump fixes the following issues: Security issues fixed: - CVE-2017-11108: Crafted input allowed remote DoS (bsc#1047873) - CVE-2017-11541: Prevent a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c (bsc#1057247). - CVE-2017-11542: Prevent a heap-based buffer over-read in the pimv1_print function in print-pim.c (bsc#1057247). - CVE-2017-11543: Prevent a buffer overflow in the sliplink_print function in print-sl.c (bsc#1057247). - CVE-2017-13011: Several protocol parsers in tcpdump could have caused a buffer overflow in util-print.c:bittok2str_internal() (bsc#1057247).
References: https://www.suse.com/support/update/announcement/2017/suse-su-20172690-1/, https://bugzilla.suse.com/1047873, https://bugzilla.suse.com/1057247, https://www.suse.com/security/cve/CVE-2017-11108, https://www.suse.com/security/cve/CVE-2017-11541, https://www.suse.com/security/cve/CVE-2017-11542, https://www.suse.com/security/cve/CVE-2017-11543, https://www.suse.com/security/cve/CVE-2017-13011
Affected packages
Package
Name: tcpdump
Purl: pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
