MEDIUM
tcpdump: Stack-based buffer over-read in print-hncp.c:print_prefix() via crafted pcap
Published Nov 25, 2018
5.5
MEDIUMCVSS 3.0
EPSS 2.36%
Description
In tcpdump 4.9.2, a stack-based buffer over-read exists in the print_prefix function of print-hncp.c via crafted packet data because of missing initialization.
Affected products
No data.
No data.
Red Hat Enterprise Linux 7
tcpdump-14:4.9.2-4.el7_7.1
Fixed · RHSA-2019:3976
Red Hat Enterprise Linux 8
tcpdump-14:4.9.2-6.el8
Fixed · RHSA-2020:1604
Red Hat Enterprise Linux 5
tcpdump
Not affected
Red Hat Enterprise Linux 6
tcpdump
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | tcpdump-14:4.9.2-4.el7_7.1 | Fixed | RHSA-2019:3976 |
| Red Hat Enterprise Linux 8 | tcpdump-14:4.9.2-6.el8 | Fixed | RHSA-2020:1604 |
| Red Hat Enterprise Linux 5 | tcpdump | Not affected | n/a |
| Red Hat Enterprise Linux 6 | tcpdump | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of tcpdump as shipped with Red Hat Enterprise Linux 7. This issue did not affect the versions of tcpdump as shipped with Red Hat Enterprise Linux 5 and 6.
Weaknesses (2)
References (13)
- http://www.securityfocus.com/bid/106098 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:3976 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-19519 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1655374 Issue Tracking
- https://github.com/zyingp/temp/blob/master/tcpdump.md x_refsource_MISCExploitMitigationThird Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516 x_refsource_CONFIRM
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62XY42U6HY3H2APR5EHNWCZ7SAQNMMJN/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNYXF3IY2X65IOD422SA6EQUULSGW7FN/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R2UDPOSGVJQIYC33SQBXMDXHH4QDSDMU/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2018-19519
- https://usn.ubuntu.com/4252-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4252-2/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2018-19519
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 25, 2018
Updated Aug 5, 2024
Reserved Nov 25, 2018
Link CVE-2018-19519
CISA Vulnrichment
Updated n/a