Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2017:2690-1

Опубликовано: 10 окт. 2017
Источник: suse-cvrf

Описание

Security update for tcpdump

This update for tcpdump fixes the following issues:

Security issues fixed:

  • CVE-2017-11108: Crafted input allowed remote DoS (bsc#1047873)
  • CVE-2017-11541: Prevent a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c (bsc#1057247).
  • CVE-2017-11542: Prevent a heap-based buffer over-read in the pimv1_print function in print-pim.c (bsc#1057247).
  • CVE-2017-11543: Prevent a buffer overflow in the sliplink_print function in print-sl.c (bsc#1057247).
  • CVE-2017-13011: Several protocol parsers in tcpdump could have caused a buffer overflow in util-print.c:bittok2str_internal() (bsc#1057247).

Список пакетов

SUSE Linux Enterprise Server 11 SP4
tcpdump-3.9.8-1.30.5.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
tcpdump-3.9.8-1.30.5.1

Описание

tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:tcpdump-3.9.8-1.30.5.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:tcpdump-3.9.8-1.30.5.1

Ссылки

Описание

tcpdump 4.9.0 has a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:tcpdump-3.9.8-1.30.5.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:tcpdump-3.9.8-1.30.5.1

Ссылки

Описание

tcpdump 4.9.0 has a heap-based buffer over-read in the pimv1_print function in print-pim.c.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:tcpdump-3.9.8-1.30.5.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:tcpdump-3.9.8-1.30.5.1

Ссылки

Описание

tcpdump 4.9.0 has a buffer overflow in the sliplink_print function in print-sl.c.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:tcpdump-3.9.8-1.30.5.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:tcpdump-3.9.8-1.30.5.1

Ссылки

Описание

Several protocol parsers in tcpdump before 4.9.2 could cause a buffer overflow in util-print.c:bittok2str_internal().


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:tcpdump-3.9.8-1.30.5.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:tcpdump-3.9.8-1.30.5.1

Ссылки
Уязвимость SUSE-SU-2017:2690-1