CRITICAL
tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c
Published Aug 27, 2022
9.1
CRITICALCVSS 3.1
EPSS 1.03%
Description
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
tcpdump
Out of support scope
Red Hat Enterprise Linux 7
tcpdump
Out of support scope
Red Hat Enterprise Linux 8
tcpdump
Not affected
Red Hat Enterprise Linux 9
tcpdump
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | tcpdump | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | tcpdump | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | tcpdump | Not affected | n/a |
| Red Hat Enterprise Linux 9 | tcpdump | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
tcpdump as shipped with Red Hat Enterprise Linux 8 and 9 is not affected by this issue.
Weaknesses (2)
References (6)
- https://access.redhat.com/security/cve/CVE-2019-15167 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2241763 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-6223 Advisory
- https://github.com/the-tcpdump-group/tcpdump/commit/a152aebfd1114376ba266ed30416be596ef9d806 x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-15167
- https://www.cve.org/CVERecord?id=CVE-2019-15167
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-15167 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2241763 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-6223 | Advisory | |
| https://github.com/the-tcpdump-group/tcpdump/commit/a152aebfd1114376ba266ed30416be596ef9d806 | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-15167 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-15167 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 27, 2022
Updated Dec 3, 2025
Reserved Aug 19, 2019
Link CVE-2019-15167
CISA Vulnrichment
Updated Jun 13, 2025
ENISA EUVD
EUVD-2019-6223 Assigner mitre
Published Aug 27, 2022
Updated Dec 3, 2025
Exploited since n/a
Link EUVD-2019-6223