security advisorydenial of servicedebian
An issue has been found in ndpi, an extensible deep packet inspection library. The Oracle protocol dissector contains an heap-based buffer over-read, which could crash the application that uses this library and . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2354-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz August 29, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ndpi Version : 1.8-1+deb9u1 CVE ID : CVE-2020-15476 An issue has been found in ndpi, an extensible deep packet inspection library. The Oracle protocol dissector contains an heap-based buffer over-read, which could crash the application that uses this library and may result in denial of service. For Debian 9 stretch, this problem has been fixed in version 1.8-1+deb9u1. We recommend that you upgrade your ndpi packages. For the detailed security status of ndpi please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ndpi Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2355-1 tackles an ndpi buffer underflow vulnerability that could result in unexpected application behavior.. ndpi Security Update, Debian LTS, Packet Inspection Library, Buffer Over-read, Denial of Service. . Severity: Critical. LinuxSecurity.com Team
Aug 29, 2020
•Critical
Debian LTS