Wind River Support Network

HomeDefectsLIN10-7081
Fixed

LIN10-7081 : Security Advisory - tcpdump - CVE-2019-15167

Created: Mar 13, 2020    Updated: Apr 10, 2020
Resolved Date: Apr 1, 2020
Previous ID: LIN1018-5846
Found In Version: 10.17.41.19
Fix Version: 10.17.41.20
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

Tcpdump is vulnerable to a buffer overflow, caused by improper bounds checking by the lmp_print_data_link_subobjs function in print-lmp.c. By sending specially-crafted data, a remote attacker could overflow a buffer and cause the application to crash.

CVEs


Live chat
Online