CVE-2019-15167
published 2022-08-27CVE-2019-15167: The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.
PriorityP339critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.90%
55.8th percentile
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.15.2 | 10.15.2 |
| apple | macos_catalina_10.15.2_security_update_2019-002_mojave_security_update_2019-007 | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tcpdump | < tcpdump 4.9.3-1 (bookworm) | tcpdump 4.9.3-1 (bookworm) |
| f5 | traffix_signaling_delivery_controller | 5.0.0 – 5.1.0 | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| tcpdump | tcpdump | < 4.9.3 | 4.9.3 |
| tcpdump | tcpdump | >= 0 < 4.9.3-1 | 4.9.3-1 |
| tcpdump | tcpdump | >= 0 < 4.9.3-1 | 4.9.3-1 |
| tcpdump | tcpdump | >= 0 < 4.9.3-1 | 4.9.3-1 |
| tcpdump | tcpdump | >= 0 < 4.9.3-1 | 4.9.3-1 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
tcpdump vulnerabilities
vendor_ubuntu·2020-01-27
CVE-2017-16808 tcpdump vulnerabilities
Title: tcpdump vulnerabilities
Summary: Several security issues were fixed in tcpdump.
USN-4252-1 fixed several vulnerabilities in tcpdump. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Multiple security issues were discovered in tcpdump. A remote attacker
could use these issues to cause tcpdump to crash, resulting in a denial of
service, or possibly execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Ubuntu
tcpdump vulnerabilities
vendor_ubuntu·2020-01-27
CVE-2017-16808 tcpdump vulnerabilities
Title: tcpdump vulnerabilities
Summary: Several security issues were fixed in tcpdump.
Multiple security issues were discovered in tcpdump. A remote attacker
could use these issues to cause tcpdump to crash, resulting in a denial of
service, or possibly execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Apple
CVE-2019-15167: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
vendor_apple·2019-12-10·CVSS 9.1
CVE-2019-15167 [CRITICAL] CVE-2019-15167: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Apple Security Update: About the security content of macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Product: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
CVE: CVE-2019-15167
Component: CVE-2019-15167
Red Hat
tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c
vendor_redhat·2019-10-02·CVSS 7.5
CVE-2018-14463 [HIGH] CWE-125 tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c
tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.
An out-of-bounds read vulnerability was discovered in tcpdump while printing VRRP packets captured in a pcap file or coming from the network. A remote attacker may abuse this flaw by sending specially crafted packets that, when printed, would trigger the flaw and crash the application.
Package: tcpdump (Red Hat Enterprise Linux 5) - Out of support scope
Package: tcpdump (Red Hat Enterprise Linux 6) - Out of support scope
Package: tcpdump (Red Hat Enterprise Linux 7) - Fix deferred
Red Hat
tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c
vendor_redhat·2019-08-18·CVSS 7.5
CVE-2019-15167 [HIGH] CWE-126 tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c
tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.
A buffer over-read flaw was found in the vrrp_print() function in the print-vrrp.c file in the VRRP parser in tcpdump, in VRRP version 3. This is a different vulnerability than CVE-2018-14463.
Statement: tcpdump as shipped with Red Hat Enterprise Linux 8 and 9 is not affected by this issue.
Package: tcpdump (Red Hat Enterprise Linux 6) - Out of support scope
Package: tcpdump (Red Hat Enterprise Linux 7) - Out of support scope
Package: tcpdump (Red Hat Enterprise Linux 8) - Not affected
Package: tcpdump (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2019-15167: tcpdump - The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:v...
vendor_debian·2019·CVSS 7.5
CVE-2019-15167 [HIGH] CVE-2019-15167: tcpdump - The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:v...
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.
Scope: local
bookworm: resolved (fixed in 4.9.3-1)
bullseye: resolved (fixed in 4.9.3-1)
forky: resolved (fixed in 4.9.3-1)
sid: resolved (fixed in 4.9.3-1)
trixie: resolved (fixed in 4.9.3-1)
Debian
CVE-2018-14463: tcpdump - The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:v...
vendor_debian·2018·CVSS 7.5
CVE-2018-14463 [HIGH] CVE-2018-14463: tcpdump - The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:v...
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.
Scope: local
bookworm: resolved (fixed in 4.9.3-1)
bullseye: resolved (fixed in 4.9.3-1)
forky: resolved (fixed in 4.9.3-1)
sid: resolved (fixed in 4.9.3-1)
trixie: resolved (fixed in 4.9.3-1)
GHSA
GHSA-x3gm-3hr2-8g66: The VRRP parser in tcpdump before 4
ghsa_unreviewed·2022-08-28·CVSS 7.5
CVE-2019-15167 [HIGH] CWE-125 GHSA-x3gm-3hr2-8g66: The VRRP parser in tcpdump before 4
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.
OSV
CVE-2019-15167: The VRRP parser in tcpdump before 4
osv·2022-08-27·CVSS 7.5
CVE-2019-15167 [HIGH] CVE-2019-15167: The VRRP parser in tcpdump before 4
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.
OSV
CVE-2018-14463: The VRRP parser in tcpdump before 4
osv·2019-10-03·CVSS 7.5
CVE-2018-14463 [HIGH] CVE-2018-14463: The VRRP parser in tcpdump before 4
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.
No detection rules found.
No public exploits indexed.
2022-08-27
Published