Errata overview
Errata ID 322
Date 2019-10-23
Source package tcpdump
Fixed in version 4.9.3-1~deb9u1
Description
This update addresses the following issues:
* Heap-based buffer over-read in aoe_print in print-aoe.c and lookup_emem in
  addrtoname.c (CVE-2017-16808)
* Mishandle printing of SMB data. (CVE-2018-10103, CVE-2018-10105)
* Buffer over-read in ldp_tlv_print() function in print-ldp.c
  (CVE-2018-14461)
* Buffer over-read in icmp_print() function in print-icmp.c (CVE-2018-14462)
* Buffer over-read in vrrp_print() function in print-vrrp.c (CVE-2018-14463)
* Buffer over-read in lmp_print_data_link_subobjs() function in print-lmp.c
  (CVE-2018-14464)
* Buffer over-read in rsvp_obj_print() function in print-rsvp.c
  (CVE-2018-14465)
* Buffer over-read in print-icmp6.c (CVE-2018-14466)
* Buffer over-read in bgp_capabilities_print() in print-bgp.c
  (CVE-2018-14467)
* Buffer over-read in mfr_print() function in print-fr.c (CVE-2018-14468)
* Buffer over-read in ikev1_n_print() function in print-isakmp.c
  (CVE-2018-14469)
* Buffer over-read in babel_print_v2() in print-babel.c (CVE-2018-14470)
* Buffer overflow in get_next_file() in tcpdump.c (CVE-2018-14879)
* Buffer over-read in ospf6_print_lshdr() function in print-ospf6.c
  (CVE-2018-14880)
* Buffer over-read in bgp_capabilities_print() function in print-bgp.c
  (CVE-2018-14881)
* Buffer over-read in print-icmp6.c (CVE-2018-14882)
* Buffer over-read in print-802_11.c (CVE-2018-16227)
* Buffer over-read in print_prefix() function in print-hncp.c
  (CVE-2018-16228)
* Buffer over-read in dccp_print_option() function in print-dccp.c
  (CVE-2018-16229)
* Buffer over-read in bgp_attr_print() function in print-bgp.c
  (CVE-2018-16230)
* Resource exhaustion in bgp_attr_print() function in print-bgp.c
  (CVE-2018-16300)
* Buffer over-read in print_trans() function in print-smb.c (CVE-2018-16451)
* Resource exhaustion in smb_fdata() funtion in smbutil.c (CVE-2018-16452)
* Buffer overflow in lmp_print_data_link_subobjs() in print-lmp.c
  (CVE-2019-15166)
Additional notes
CVE ID CVE-2017-16808
CVE-2018-10103
CVE-2018-10105
CVE-2018-14461
CVE-2018-14462
CVE-2018-14463
CVE-2018-14464
CVE-2018-14465
CVE-2018-14466
CVE-2018-14467
CVE-2018-14468
CVE-2018-14469
CVE-2018-14470
CVE-2018-14879
CVE-2018-14880
CVE-2018-14881
CVE-2018-14882
CVE-2018-16227
CVE-2018-16228
CVE-2018-16229
CVE-2018-16230
CVE-2018-16300
CVE-2018-16451
CVE-2018-16452
CVE-2019-15166
UCS Bug number #50396