ALAS2-2023-2119

Related Vulnerabilities: CVE-2019-15167  

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463. (CVE-2019-15167)

ALAS2-2023-2119


Amazon Linux 2 Security Advisory: ALAS-2023-2119
Advisory Release Date: 2023-07-05 22:01 Pacific
Advisory Updated Date: 2023-07-19 22:26 Pacific
Severity: Medium

Issue Overview:

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463. (CVE-2019-15167)


Affected Packages:

tcpdump


Issue Correction:
Run yum update tcpdump to update your system.

New Packages:
aarch64:
    tcpdump-4.9.2-4.amzn2.1.0.1.aarch64
    tcpdump-debuginfo-4.9.2-4.amzn2.1.0.1.aarch64

i686:
    tcpdump-4.9.2-4.amzn2.1.0.1.i686
    tcpdump-debuginfo-4.9.2-4.amzn2.1.0.1.i686

src:
    tcpdump-4.9.2-4.amzn2.1.0.1.src

x86_64:
    tcpdump-4.9.2-4.amzn2.1.0.1.x86_64
    tcpdump-debuginfo-4.9.2-4.amzn2.1.0.1.x86_64