CVE-2019-15167Buffer Over-read in Tcpdump

Severity
9.1CRITICALNVD
NVD7.5CNA7.5OSV7.5
EPSS
0.1%
top 69.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 27
Latest updateAug 28

Description

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages7 packages

debiandebian/tcpdump< tcpdump 4.9.3-1 (bookworm)
NVDtcpdump/tcpdump< 4.9.3
Debiantcpdump/tcpdump< 4.9.3-1+3
NVDapple/mac_os_x< 10.15.2

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 29, 30, 31, Enterprise Linux 7.0, 8.0

Patches

🔴Vulnerability Details

5
GHSA
GHSA-x3gm-3hr2-8g66: The VRRP parser in tcpdump before 42022-08-28
OSV
CVE-2019-15167: The VRRP parser in tcpdump before 42022-08-27
CVEList
CVE-2019-15167: The VRRP parser in tcpdump before 42022-08-27
CVEList
CVE-2018-14463: The VRRP parser in tcpdump before 42019-10-03
OSV
CVE-2018-14463: The VRRP parser in tcpdump before 42019-10-03

📋Vendor Advisories

7
Ubuntu
tcpdump vulnerabilities2020-01-27
Ubuntu
tcpdump vulnerabilities2020-01-27
Apple
CVE-2019-15167: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra2019-12-10
Red Hat
tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c2019-10-02
Red Hat
tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c2019-08-18

🕵️Threat Intelligence

1
Sentinelone
macOS Catalina 10.15.2 Update: What's New2019-12-12