SUSE-SU-2019:14191-1

    Dashboard / Vulnerabilities / SUSE-SU-2019:14191-1

    SUSE-SU-2019:14191-1

    Published: 15 Oct 2019Last Modified: 4 Feb 2026

    Summary: Security update for tcpdump

    Details: This update for tcpdump fixes the following issues: Security issues fixed: - CVE-2017-12995: Fixed an infinite loop in the DNS parser that allowed remote DoS (bsc#1057247). - CVE-2017-12893: Fixed a buffer over-read in the SMB/CIFS parser that allowed remote DoS (bsc#1057247). - CVE-2017-12894: Fixed a buffer over-read in several protocol parsers that allowed remote DoS (bsc#1057247). - CVE-2017-12896: Fixed a buffer over-read in the ISAKMP parser that allowed remote DoS (bsc#1057247). - CVE-2017-12897: Fixed a buffer over-read in the ISO CLNS parser that allowed remote DoS (bsc#1057247). - CVE-2017-12898: Fixed a buffer over-read in the NFS parser that allowed remote DoS (bsc#1057247). - CVE-2017-12899: Fixed a buffer over-read in the DECnet parser that allowed remote DoS (bsc#1057247). - CVE-2017-12900: Fixed a buffer over-read in the in several protocol parsers that allowed remote DoS (bsc#1057247). - CVE-2017-12901: Fixed a buffer over-read in the EIGRP parser that allowed remote DoS (bsc#1057247). - CVE-2017-12902: Fixed a buffer over-read in the Zephyr parser that allowed remote DoS (bsc#1057247). - CVE-2017-12985: Fixed a buffer over-read in the IPv6 parser that allowed remote DoS (bsc#1057247). - CVE-2017-12986: Fixed a buffer over-read in the IPv6 routing header parser that allowed remote DoS (bsc#1057247). - CVE-2017-12987: Fixed a buffer over-read in the 802.11 parser that allowed remote DoS (bsc#1057247). - CVE-2017-12988: Fixed a buffer over-read in the telnet parser that allowed remote DoS (bsc#1057247). - CVE-2017-12991: Fixed a buffer over-read in the BGP parser that allowed remote DoS (bsc#1057247). - CVE-2017-12992: Fixed a buffer over-read in the RIPng parser that allowed remote DoS (bsc#1057247). - CVE-2017-12993: Fixed a buffer over-read in the Juniper protocols parser that allowed remote DoS (bsc#1057247). - CVE-2017-12996: Fixed a buffer over-read in the PIMv2 parser that allowed remote DoS (bsc#1057247). - CVE-2017-12998: Fixed a buffer over-read in the IS-IS parser that allowed remote DoS (bsc#1057247). - CVE-2017-12999: Fixed a buffer over-read in the IS-IS parser that allowed remote DoS (bsc#1057247). - CVE-2017-13001: Fixed a buffer over-read in the NFS parser that allowed remote DoS (bsc#1057247). - CVE-2017-13002: Fixed a buffer over-read in the AODV parser that allowed remote DoS (bsc#1057247). - CVE-2017-13003: Fixed a buffer over-read in the LMP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13004: Fixed a buffer over-read in the Juniper protocols parser that allowed remote DoS (bsc#1057247). - CVE-2017-13005: Fixed a buffer over-read in the NFS parser that allowed remote DoS (bsc#1057247). - CVE-2017-13006: Fixed a buffer over-read in the L2TP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13008: Fixed a buffer over-read in the IEEE 802.11 parser that allowed remote DoS (bsc#1057247). - CVE-2017-13009: Fixed a buffer over-read in the IPv6 mobility parser that allowed remote DoS (bsc#1057247). - CVE-2017-13010: Fixed a buffer over-read in the BEEP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13012: Fixed a buffer over-read in the ICMP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13013: Fixed a buffer over-read in the ARP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13014: Fixed a buffer over-read in the White Board protocol parser that allowed remote DoS (bsc#1057247). - CVE-2017-13016: Fixed a buffer over-read in the ISO ES-IS parser that allowed remote DoS (bsc#1057247). - CVE-2017-13017: Fixed a buffer over-read in the DHCPv6 parser that allowed remote DoS (bsc#1057247). - CVE-2017-13018: Fixed a buffer over-read in the PGM parser that allowed remote DoS (bsc#1057247). - CVE-2017-13019: Fixed a buffer over-read in the PGM parser that allowed remote DoS (bsc#1057247). - CVE-2017-13021: Fixed a buffer over-read in the ICMPv6 parser that allowed remote DoS (bsc#1057247). - CVE-2017-13022: Fixed a buffer over-read in the IP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13023: Fixed a buffer over-read in the IPv6 mobility parser that allowed remote DoS (bsc#1057247). - CVE-2017-13024: Fixed a buffer over-read in the IPv6 mobility parser that allowed remote DoS (bsc#1057247). - CVE-2017-13025: Fixed a buffer over-read in the IPv6 mobility parser that allowed remote DoS (bsc#1057247). - CVE-2017-13027: Fixed a buffer over-read in the LLDP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13028: Fixed a buffer over-read in the BOOTP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13029: Fixed a buffer over-read in the PPP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13030: Fixed a buffer over-read in the PIM parser that allowed remote DoS (bsc#1057247). - CVE-2017-13031: Fixed a buffer over-read in the IPv6 fragmentation header parser that allowed remote DoS (bsc#1057247). - CVE-2017-13032: Fixed a buffer over-read in the RADIUS parser that allowed remote DoS (bsc#1057247). - CVE-2017-13034: Fixed a buffer over-read in the PGM parser that allowed remote DoS (bsc#1057247). - CVE-2017-13035: Fixed a buffer over-read in the ISO IS-IS parser that allowed remote DoS (bsc#1057247). - CVE-2017-13036: Fixed a buffer over-read in the OSPFv3 parser that allowed remote DoS (bsc#1057247). - CVE-2017-13037: Fixed a buffer over-read in the IP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13038: Fixed a buffer over-read in the PPP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13041: Fixed a buffer over-read in the ICMPv6 parser that allowed remote DoS (bsc#1057247). - CVE-2017-13047: Fixed a buffer over-read in the ISO ES-IS parser that allowed remote DoS (bsc#1057247). - CVE-2017-13048: Fixed a buffer over-read in the RSVP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13049: Fixed a buffer over-read in the Rx protocol parser that allowed remote DoS (bsc#1057247). - CVE-2017-13051: Fixed a buffer over-read in the RSVP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13053: Fixed a buffer over-read in the BGP parser that allowed remote DoS (bsc#1057247). - CVE-2017-13055: Fixed a buffer over-read in the ISO IS-IS parser that allowed remote DoS (bsc#1057247). - CVE-2017-13687: Fixed a buffer over-read in the Cisco HDLC parser that allowed remote DoS (bsc#1057247). - CVE-2017-13688: Fixed a buffer over-read in the OLSR parser that allowed remote DoS (bsc#1057247). - CVE-2017-13689: Fixed a buffer over-read in the IKEv1 parser that allowed remote DoS (bsc#1057247). - CVE-2017-13725: Fixed a buffer over-read in the IPv6 routing header parser that allowed remote DoS (bsc#1057247). - CVE-2018-10103: Fixed a mishandling of the printing of SMB data (bsc#1153098). - CVE-2018-10105: Fixed a mishandling of the printing of SMB data (bsc#1153098). - CVE-2018-14461: Fixed a buffer over-read in print-ldp.c:ldp_tlv_print (bsc#1153098). - CVE-2018-14462: Fixed a buffer over-read in print-icmp.c:icmp_print (bsc#1153098). - CVE-2018-14463: Fixed a buffer over-read in print-vrrp.c:vrrp_print (bsc#1153098). - CVE-2018-14464: Fixed a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs (bsc#1153098). - CVE-2018-14465: Fixed a buffer over-read in print-rsvp.c:rsvp_obj_print (bsc#1153098). - CVE-2018-14466: Fixed a buffer over-read in print-rx.c:rx_cache_find (bsc#1153098). - CVE-2018-14467: Fixed a buffer over-read in print-bgp.c:bgp_capabilities_print (bsc#1153098). - CVE-2018-14468: Fixed a buffer over-read in print-fr.c:mfr_print (bsc#1153098). - CVE-2018-14469: Fixed a buffer over-read in print-isakmp.c:ikev1_n_print (bsc#1153098). - CVE-2018-14881: Fixed a buffer over-read in the BGP parser (bsc#1153098). - CVE-2018-14882: Fixed a buffer over-read in the ICMPv6 parser (bsc#1153098). - CVE-2018-16229: Fixed a buffer over-read in the DCCP parser (bsc#1153098). - CVE-2018-16230: Fixed a buffer over-read in the BGP parser in print-bgp.c:bgp_attr_print (bsc#1153098). - CVE-2018-16300: Fixed an unlimited recursion in the BGP parser that allowed denial-of-service by stack consumption (bsc#1153098). - CVE-2018-16301: Fixed a buffer overflow (bsc#1153332 bsc#1153098). - CVE-2018-16451: Fixed several buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN (bsc#1153098). - CVE-2018-16452: Fixed a stack exhaustion in smbutil.c:smb_fdata (bsc#1153098). - CVE-2019-15166: Fixed a bounds check in lmp_print_data_link_subobjs (bsc#1153098).

    References: https://www.suse.com/support/update/announcement/2019/suse-su-201914191-1/, https://bugzilla.suse.com/1057247, https://bugzilla.suse.com/1153098, https://bugzilla.suse.com/1153332, https://www.suse.com/security/cve/CVE-2017-12893, https://www.suse.com/security/cve/CVE-2017-12894, https://www.suse.com/security/cve/CVE-2017-12896, https://www.suse.com/security/cve/CVE-2017-12897, https://www.suse.com/security/cve/CVE-2017-12898, https://www.suse.com/security/cve/CVE-2017-12899, https://www.suse.com/security/cve/CVE-2017-12900, https://www.suse.com/security/cve/CVE-2017-12901, https://www.suse.com/security/cve/CVE-2017-12902, https://www.suse.com/security/cve/CVE-2017-12985, https://www.suse.com/security/cve/CVE-2017-12986, https://www.suse.com/security/cve/CVE-2017-12987, https://www.suse.com/security/cve/CVE-2017-12988, https://www.suse.com/security/cve/CVE-2017-12991, https://www.suse.com/security/cve/CVE-2017-12992, https://www.suse.com/security/cve/CVE-2017-12993, https://www.suse.com/security/cve/CVE-2017-12995, https://www.suse.com/security/cve/CVE-2017-12996, https://www.suse.com/security/cve/CVE-2017-12998, https://www.suse.com/security/cve/CVE-2017-12999, https://www.suse.com/security/cve/CVE-2017-13001, https://www.suse.com/security/cve/CVE-2017-13002, https://www.suse.com/security/cve/CVE-2017-13003, https://www.suse.com/security/cve/CVE-2017-13004, https://www.suse.com/security/cve/CVE-2017-13005, https://www.suse.com/security/cve/CVE-2017-13006, https://www.suse.com/security/cve/CVE-2017-13008, https://www.suse.com/security/cve/CVE-2017-13009, https://www.suse.com/security/cve/CVE-2017-13010, https://www.suse.com/security/cve/CVE-2017-13012, https://www.suse.com/security/cve/CVE-2017-13013, https://www.suse.com/security/cve/CVE-2017-13014, https://www.suse.com/security/cve/CVE-2017-13016, https://www.suse.com/security/cve/CVE-2017-13017, https://www.suse.com/security/cve/CVE-2017-13018, https://www.suse.com/security/cve/CVE-2017-13019, https://www.suse.com/security/cve/CVE-2017-13021, https://www.suse.com/security/cve/CVE-2017-13022, https://www.suse.com/security/cve/CVE-2017-13023, https://www.suse.com/security/cve/CVE-2017-13024, https://www.suse.com/security/cve/CVE-2017-13025, https://www.suse.com/security/cve/CVE-2017-13027, https://www.suse.com/security/cve/CVE-2017-13028, https://www.suse.com/security/cve/CVE-2017-13029, https://www.suse.com/security/cve/CVE-2017-13030, https://www.suse.com/security/cve/CVE-2017-13031, https://www.suse.com/security/cve/CVE-2017-13032, https://www.suse.com/security/cve/CVE-2017-13034, https://www.suse.com/security/cve/CVE-2017-13035, https://www.suse.com/security/cve/CVE-2017-13036, https://www.suse.com/security/cve/CVE-2017-13037, https://www.suse.com/security/cve/CVE-2017-13038, https://www.suse.com/security/cve/CVE-2017-13041, https://www.suse.com/security/cve/CVE-2017-13047, https://www.suse.com/security/cve/CVE-2017-13048, https://www.suse.com/security/cve/CVE-2017-13049, https://www.suse.com/security/cve/CVE-2017-13051, https://www.suse.com/security/cve/CVE-2017-13053, https://www.suse.com/security/cve/CVE-2017-13055, https://www.suse.com/security/cve/CVE-2017-13687, https://www.suse.com/security/cve/CVE-2017-13688, https://www.suse.com/security/cve/CVE-2017-13689, https://www.suse.com/security/cve/CVE-2017-13725, https://www.suse.com/security/cve/CVE-2018-10103, https://www.suse.com/security/cve/CVE-2018-10105, https://www.suse.com/security/cve/CVE-2018-14461, https://www.suse.com/security/cve/CVE-2018-14462, https://www.suse.com/security/cve/CVE-2018-14463, https://www.suse.com/security/cve/CVE-2018-14464, https://www.suse.com/security/cve/CVE-2018-14465, https://www.suse.com/security/cve/CVE-2018-14466, https://www.suse.com/security/cve/CVE-2018-14467, https://www.suse.com/security/cve/CVE-2018-14468, https://www.suse.com/security/cve/CVE-2018-14469, https://www.suse.com/security/cve/CVE-2018-14881, https://www.suse.com/security/cve/CVE-2018-14882, https://www.suse.com/security/cve/CVE-2018-16229, https://www.suse.com/security/cve/CVE-2018-16230, https://www.suse.com/security/cve/CVE-2018-16300, https://www.suse.com/security/cve/CVE-2018-16301, https://www.suse.com/security/cve/CVE-2018-16451, https://www.suse.com/security/cve/CVE-2018-16452, https://www.suse.com/security/cve/CVE-2019-15166

    Affected packages

    Package

    Name: tcpdump

    Purl: pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.9.8-1.30.13.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High