Back

CRITICAL

tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c

Published Aug 27, 2022

Description

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.

Affected products

Remediation

Red Hat statement

tcpdump as shipped with Red Hat Enterprise Linux 8 and 9 is not affected by this issue.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 27, 2022
Updated Dec 3, 2025
Reserved Aug 19, 2019
CISA Vulnrichment
Updated Jun 13, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 18, 2019
ENISA EUVD
Assigner mitre
Published Aug 27, 2022
Updated Dec 3, 2025
Exploited since n/a
EUVD-2019-6223