Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2019:14191-1 Important: tcpdump DoS Issues Resolved

suse
Calendar Grey October 15, 2019
Dist Suse Esm H88
An update has been released for tcpdump addressing 83 significant vulnerabilities classified as critical, as rated by SUSE. Ensure your security by upgrading immediately.
An update that fixes 83 vulnerabilities is now available

Summary

This update for tcpdump fixes the following issues: Security issues fixed: - CVE-2017-12995: Fixed an infinite loop in the DNS parser that allowed remote DoS (bsc#1057247). - CVE-2017-12893: Fixed a buffer over-read in the SMB/CIFS parser that allowed remote DoS (bsc#1057247). - CVE-2017-12894: Fixed a buffer over-read in several protocol parsers that allowed remote DoS (bsc#1057247). - CVE-2017-12896: Fixed a buffer over-read in the ISAKMP parser that allowed remote DoS (bsc#1057247). - CVE-2017-12897: Fixed a buffer over-read in the ISO CLNS parser that allowed remote DoS (bsc#1057247). - CVE-2017-12898: Fixed a buffer over-read in the NFS parser that allowed remote DoS (bsc#1057247). - CVE-2017-12899: Fixed a buffer over-read in the DECnet parser that allowed remote DoS (bsc#1057247).

References

#1057247 #1153098 #1153332

Cross- CVE-2017-12893 CVE-2017-12894 CVE-2017-12896

CVE-2017-12897 CVE-2017-12898 CVE-2017-12899

CVE-2017-12900 CVE-2017-12901 CVE-2017-12902

CVE-2017-12985 CVE-2017-12986 CVE-2017-12987

CVE-2017-12988 CVE-2017-12991 CVE-2017-12992

CVE-2017-12993 CVE-2017-12995 CVE-2017-12996

CVE-2017-12998 CVE-2017-12999 CVE-2017-13001

CVE-2017-13002 CVE-2017-13003 CVE-2017-13004

CVE-2017-13005 CVE-2017-13006 CVE-2017-13008

CVE-2017-13009 CVE-2017-13010 CVE-2017-13012

CVE-2017-13013 CVE-2017-13014 CVE-2017-13016

CVE-2017-13017 CVE-2017-13018 CVE-2017-13019

CVE-2017-13021 CVE-2017-13022 CVE-2017-13023

CVE-2017-13024 CVE-2017-13025 CVE-2017-13027

CVE-2017-13028 CVE-2017-13029 CVE-2017-13030

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:14191-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here