Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE Linux Enterprise Server 12-SP5: 2020:3360-1 Security Fix for Tcpdump

suse
Calendar Grey November 17, 2020
Dist Suse Esm H88
New patch released for tcpdump addressing several vulnerabilities, classified as moderate severity. Please adhere to the provided installation guide for updates.
An update that fixes 29 vulnerabilities is now available

Summary

This update for tcpdump fixes the following issues: - CVE-2020-8037: Fixed an issue where PPP decapsulator did not allocate the right buffer size (bsc#1178466). The previous update of tcpdump already fixed variuous Buffer overflow/overread vulnerabilities [bsc#1153098, bsc#1153332] - CVE-2017-16808 (AoE) - CVE-2018-14468 (FrameRelay) - CVE-2018-14469 (IKEv1) - CVE-2018-14470 (BABEL) - CVE-2018-14466 (AFS/RX) - CVE-2018-14461 (LDP) - CVE-2018-14462 (ICMP) - CVE-2018-14465 (RSVP) - CVE-2018-14464 (LMP) - CVE-2019-15166 (LMP) - CVE-2018-14880 (OSPF6) - CVE-2018-14882 (RPL) - CVE-2018-16227 (802.11) - CVE-2018-16229 (DCCP) - CVE-2018-14467 (BGP) - CVE-2018-14881 (BGP) - CVE-2018-16230 (BGP) - CVE-2018-16300 (BGP) - CVE-2018-14463 (VRRP) - CVE-2019-15167 (VRRP) - CVE-2018-14879 (tcpdump -V)

References

#1153098 #1153332 #1178466

Cross- CVE-2017-16808 CVE-2018-10103 CVE-2018-10105

CVE-2018-14461 CVE-2018-14462 CVE-2018-14463

CVE-2018-14464 CVE-2018-14465 CVE-2018-14466

CVE-2018-14467 CVE-2018-14468 CVE-2018-14469

CVE-2018-14470 CVE-2018-14879 CVE-2018-14880

CVE-2018-14881 CVE-2018-14882 CVE-2018-16227

CVE-2018-16228 CVE-2018-16229 CVE-2018-16230

CVE-2018-16300 CVE-2018-16301 CVE-2018-16451

CVE-2018-16452 CVE-2019-1010220 CVE-2019-15166

CVE-2019-15167 CVE-2020-8037

Affected Products:

SUSE Linux Enterprise Server 12-SP5

https://www.suse.com/security/cve/CVE-2017-16808.html

https://www.suse.com/security/cve/CVE-2018-10103.html

https://www.suse.com/security/cve/CVE-2018-10105.html

https://www.suse.com/security/cve/CVE-2018-14461.html

Announcement ID: SUSE-SU-2020:3360-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here