Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-1010220

Опубликовано: 01 авг. 2019
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file.

Отчет

This flaw was found to be a duplicate of CVE-2018-19519. Please see https://access.redhat.com/security/cve/CVE-2018-19519 for information about affected products and security errata.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5tcpdumpNot affected
Red Hat Enterprise Linux 6tcpdumpNot affected
Red Hat Enterprise Linux 7tcpdumpNot affected
Red Hat Enterprise Linux 8tcpdumpNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1735549tcpdump: buffer over-read in function print_prefix in print-hncp.c

EPSS

Процентиль: 69%
0.01348
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 7 лет назад

tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file.

CVSS3: 3.3
nvd
около 7 лет назад

tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file.

CVSS3: 3.3
debian
около 7 лет назад

tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. T ...

CVSS3: 3.3
github
больше 4 лет назад

tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file.

CVSS3: 3.3
fstec
около 7 лет назад

Уязвимость утилиты для перехвата и анализа сетевого трафика tcpdump, вызванная переполнением буфера, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 69%
0.01348
Низкий

5.4 Medium

CVSS3