[Secure-testing-team] Bug#881862: tcpdump: CVE-2017-16808: heap-based buffer over-read related to aoe_print in print-aoe.c and lookup_emem in addrtoname.c

Salvatore Bonaccorso carnil at debian.org
Wed Nov 15 21:04:18 UTC 2017


Source: tcpdump
Version: 4.9.2-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/the-tcpdump-group/tcpdump/issues/645
Control: found -1 4.9.2-1~deb9u1
Control: found -1 4.9.2-1~deb8u1

Hi,

the following vulnerability was published for tcpdump. This is
basically just to track the issue in Debian BTS. Upstream said that
[1] is not the first report and the issue is been reported alrady, and
will be fixed in a future release. No further information in [1] apart
that from upstream project.

CVE-2017-16808[0]:
| tcpdump 4.9.2 has a heap-based buffer over-read related to aoe_print in
| print-aoe.c and lookup_emem in addrtoname.c.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-16808
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16808
[1] https://github.com/the-tcpdump-group/tcpdump/issues/645

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Secure-testing-team mailing list