Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 32 Advisory: 2020-c5e78886d6 Critical Tcpdump Memory Issue

fedora
Calendar Grey December 5, 2020
Dist Fedora Esm H88
Fedora 32's essential patch for Tcpdump addresses memory vulnerabilities, ensuring secure network analysis for every user.
Security fix for CVE-2020-8037

Summary

Tcpdump is a command-line tool for monitoring network traffic.

Tcpdump can capture and display the packet headers on a particular

network interface or on all interfaces. Tcpdump can display all of

the packet headers, or just the ones that match particular criteria.

Install tcpdump if you need a program to monitor network traffic.

Security fix for CVE-2020-8037

* Fri Nov 27 2020 Michal Ruprich - 14:4.9.3-4

- Fix for CVE-2020-8037

[ 1 ] Bug #1895080 - CVE-2020-8037 tcpdump: ppp decapsulator can be convinced to allocate a large amount of memory

https://bugzilla.redhat.com/show_bug.cgi?id=1895080

su -c 'dnf upgrade --advisory FEDORA-2020-c5e78886d6' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 4.9.3
Release: 4.fc32
Summary: A network traffic monitoring tool

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here