UbuntuUpdates.org

Package "tcpdump"

Name: tcpdump

Description:

command-line network traffic analyzer

Latest version: 4.9.3-4ubuntu0.1
Release: focal (20.04)
Level: security
Repository: main
Homepage: https://www.tcpdump.org/

Links


Download "tcpdump"


Other versions of "tcpdump" in Focal

Repository Area Version
base main 4.9.3-4
updates main 4.9.3-4ubuntu0.3

Changelog

Version: 4.9.3-4ubuntu0.1 2022-04-11 09:06:18 UTC

  tcpdump (4.9.3-4ubuntu0.1) focal-security; urgency=medium

  * SECURITY UPDATE: buffer overflow in read_infile
    - debian/patches/CVE-2018-16301.patch: Add check of
      file size before allocating and reading content in
      tcpdump.c and netdissect-stdinc.h.
    - CVE-2018-16301
  * SECURITY UPDATE: resource exhaustion with big packets
    - debian/patches/CVE-2020-8037.patch: Add a limit to the
      amount of space that can be allocated when reading the
      packet.
    - CVE-2020-8037

 -- David Fernandez Gonzalez <email address hidden> Thu, 07 Apr 2022 13:15:51 +0200

CVE-2018-16301 The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacke
CVE-2020-8037 The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.



About   -   Send Feedback to @ubuntu_updates