UBUNTU-CVE-2018-14938
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-14938
UBUNTU-CVE-2018-14938
Summary:
Details: An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handle_prism during caplen processing. If the caplen is less than 144, one can cause an integer overflow in the function handle_80211, which will result in an out-of-bounds read and may allow access to sensitive memory (or a denial of service).
References: https://ubuntu.com/security/CVE-2018-14938, https://github.com/simsong/tcpflow/commit/a4e1cd14eb5ccc51ed271b65b3420f7d692c40eb, https://github.com/simsong/tcpflow/issues/182, https://ubuntu.com/security/notices/USN-3955-1, https://www.cve.org/CVERecord?id=CVE-2018-14938
Affected packages
Package
Name: tcpflow
Purl: pkg:deb/ubuntu/[email protected]+repack1-2ubuntu0.1~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
