ALAS-2015-557

Related Vulnerabilities: CVE-2015-0261   CVE-2015-2154  

Integer signedness error in the mobility_opt_print function in the IPv6 mobility printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) or possibly execute arbitrary code via a negative length value. (CVE-2015-0261) The osi_print_cksum function in print-isoclns.c in the ethernet printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) length, (2) offset, or (3) base pointer checksum value. (CVE-2015-2154)

ALAS-2015-557


Amazon Linux AMI Security Advisory: ALAS-2015-557
Advisory Release Date: 2015-07-07 12:31 Pacific
Advisory Updated Date: 2015-07-07 22:25 Pacific
Severity: Medium

Issue Overview:

Integer signedness error in the mobility_opt_print function in the IPv6 mobility printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) or possibly execute arbitrary code via a negative length value. (CVE-2015-0261)

The osi_print_cksum function in print-isoclns.c in the ethernet printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) length, (2) offset, or (3) base pointer checksum value. (CVE-2015-2154)


Affected Packages:

tcpdump


Issue Correction:
Run yum update tcpdump to update your system.

New Packages:
i686:
    tcpdump-4.0.0-3.20090921gitdf3cb4.2.10.amzn1.i686
    tcpdump-debuginfo-4.0.0-3.20090921gitdf3cb4.2.10.amzn1.i686

src:
    tcpdump-4.0.0-3.20090921gitdf3cb4.2.10.amzn1.src

x86_64:
    tcpdump-debuginfo-4.0.0-3.20090921gitdf3cb4.2.10.amzn1.x86_64
    tcpdump-4.0.0-3.20090921gitdf3cb4.2.10.amzn1.x86_64