Wind River Support Network

HomeDefectsLIN9-9694
Fixed

LIN9-9694 : Security Advisory - tcpdump - CVE-2019-15167

Created: Mar 13, 2020    Updated: Apr 13, 2020
Resolved Date: Mar 15, 2020
Previous ID: LIN10-7082
Found In Version: 9.0.0.24
Fix Version: 9.0.0.25
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

Tcpdump is vulnerable to a buffer overflow, caused by improper bounds checking by the lmp_print_data_link_subobjs function in print-lmp.c. By sending specially-crafted data, a remote attacker could overflow a buffer and cause the application to crash.

CVEs


Live chat
Online