SUSE-SU-2019:2674-1

    Dashboard / Vulnerabilities / SUSE-SU-2019:2674-1

    SUSE-SU-2019:2674-1

    Published: 15 Oct 2019Last Modified: 4 Feb 2026

    Summary: Security update for tcpdump

    Details: This update for tcpdump fixes the following issues: - CVE-2017-16808: Fixed a heap-based buffer over-read related to aoe_print and lookup_emem (bsc#1068716 bsc#1153098). - CVE-2018-10103: Fixed a mishandling of the printing of SMB data (bsc#1153098). - CVE-2018-10105: Fixed a mishandling of the printing of SMB data (bsc#1153098). - CVE-2018-14461: Fixed a buffer over-read in print-ldp.c:ldp_tlv_print (bsc#1153098). - CVE-2018-14462: Fixed a buffer over-read in print-icmp.c:icmp_print (bsc#1153098). - CVE-2018-14463: Fixed a buffer over-read in print-vrrp.c:vrrp_print (bsc#1153098). - CVE-2018-14464: Fixed a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs (bsc#1153098). - CVE-2018-14465: Fixed a buffer over-read in print-rsvp.c:rsvp_obj_print (bsc#1153098). - CVE-2018-14466: Fixed a buffer over-read in print-rx.c:rx_cache_find (bsc#1153098). - CVE-2018-14467: Fixed a buffer over-read in print-bgp.c:bgp_capabilities_print (bsc#1153098). - CVE-2018-14468: Fixed a buffer over-read in print-fr.c:mfr_print (bsc#1153098). - CVE-2018-14469: Fixed a buffer over-read in print-isakmp.c:ikev1_n_print (bsc#1153098). - CVE-2018-14470: Fixed a buffer over-read in print-babel.c:babel_print_v2 (bsc#1153098). - CVE-2018-14879: Fixed a buffer overflow in the command-line argument parser (bsc#1153098). - CVE-2018-14880: Fixed a buffer over-read in the OSPFv3 parser (bsc#1153098). - CVE-2018-14881: Fixed a buffer over-read in the BGP parser (bsc#1153098). - CVE-2018-14882: Fixed a buffer over-read in the ICMPv6 parser (bsc#1153098). - CVE-2018-16227: Fixed a buffer over-read in the IEEE 802.11 parser in print-802_11.c for the Mesh Flags subfield (bsc#1153098). - CVE-2018-16228: Fixed a buffer over-read in the HNCP parser (bsc#1153098). - CVE-2018-16229: Fixed a buffer over-read in the DCCP parser (bsc#1153098). - CVE-2018-16230: Fixed a buffer over-read in the BGP parser in print-bgp.c:bgp_attr_print (bsc#1153098). - CVE-2018-16300: Fixed an unlimited recursion in the BGP parser that allowed denial-of-service by stack consumption (bsc#1153098). - CVE-2018-16301: Fixed a buffer overflow (bsc#1153332 bsc#1153098). - CVE-2018-16451: Fixed several buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN (bsc#1153098). - CVE-2018-16452: Fixed a stack exhaustion in smbutil.c:smb_fdata (bsc#1153098). - CVE-2019-15166: Fixed a bounds check in lmp_print_data_link_subobjs (bsc#1153098). - CVE-2019-15167: Fixed a vulnerability in VRRP (bsc#1153098).

    References: https://www.suse.com/support/update/announcement/2019/suse-su-20192674-1/, https://bugzilla.suse.com/1068716, https://bugzilla.suse.com/1153098, https://bugzilla.suse.com/1153332, https://www.suse.com/security/cve/CVE-2017-16808, https://www.suse.com/security/cve/CVE-2018-10103, https://www.suse.com/security/cve/CVE-2018-10105, https://www.suse.com/security/cve/CVE-2018-14461, https://www.suse.com/security/cve/CVE-2018-14462, https://www.suse.com/security/cve/CVE-2018-14463, https://www.suse.com/security/cve/CVE-2018-14464, https://www.suse.com/security/cve/CVE-2018-14465, https://www.suse.com/security/cve/CVE-2018-14466, https://www.suse.com/security/cve/CVE-2018-14467, https://www.suse.com/security/cve/CVE-2018-14468, https://www.suse.com/security/cve/CVE-2018-14469, https://www.suse.com/security/cve/CVE-2018-14470, https://www.suse.com/security/cve/CVE-2018-14879, https://www.suse.com/security/cve/CVE-2018-14880, https://www.suse.com/security/cve/CVE-2018-14881, https://www.suse.com/security/cve/CVE-2018-14882, https://www.suse.com/security/cve/CVE-2018-16227, https://www.suse.com/security/cve/CVE-2018-16228, https://www.suse.com/security/cve/CVE-2018-16229, https://www.suse.com/security/cve/CVE-2018-16230, https://www.suse.com/security/cve/CVE-2018-16300, https://www.suse.com/security/cve/CVE-2018-16301, https://www.suse.com/security/cve/CVE-2018-16451, https://www.suse.com/security/cve/CVE-2018-16452, https://www.suse.com/security/cve/CVE-2019-1010220, https://www.suse.com/security/cve/CVE-2019-15166, https://www.suse.com/security/cve/CVE-2019-15167

    Affected packages

    Package

    Name: tcpdump

    Purl: pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.9.2-3.9.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High