Wind River Support Network

HomeDefectsLIN8-12219
Fixed

LIN8-12219 : Security Advisory - tcpdump - CVE-2019-15167

Created: Mar 13, 2020    Updated: Apr 25, 2020
Resolved Date: Apr 20, 2020
Previous ID: LIN9-9695
Found In Version: 8.0.0.32
Fix Version: 8.0.0.33
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

Tcpdump is vulnerable to a buffer overflow, caused by improper bounds checking by the lmp_print_data_link_subobjs function in print-lmp.c. By sending specially-crafted data, a remote attacker could overflow a buffer and cause the application to crash.

CVEs


Live chat
Online