SB2019100320 - Out-of-bounds read in tcpdump (Alpine package)
Published: October 3, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2018-16301)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in libpcap when during pcapng reading. A remote attacker can pass specially crafted data to the application that uses the affected library, trigger out-of-bounds read error and read contents of memory on the system or crash the application.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=dd5d221102dfcc65b44c43c915d134e830e8d599
- https://git.alpinelinux.org/aports/commit/?id=43630260e7496764500acd52f55ccf1a96ea3095
- https://git.alpinelinux.org/aports/commit/?id=552c3620773db0fb6a4d1e714eaa49b6a16de052
- https://git.alpinelinux.org/aports/commit/?id=e3e3e3952958b31bf6f3e01e6c73b30e3e126745
- https://git.alpinelinux.org/aports/commit/?id=afa32cc79b9e40d4a1612be4abc04540bf1f3e45