Amazon Linux AMI Security Advisory: ALAS-2022-1641
Advisory Release Date: 2022-12-01 17:33 Pacific
Advisory Updated Date: 2022-12-10 00:46 Pacific
Severity:
Medium
References:
CVE-2019-15167
Issue Overview:
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463. (CVE-2019-15167)
Affected Packages:
tcpdump
Issue Correction:
Run yum update tcpdump to update your system.
New Packages:
i686:
tcpdump-4.9.2-4.24.amzn1.i686
tcpdump-debuginfo-4.9.2-4.24.amzn1.i686
src:
tcpdump-4.9.2-4.24.amzn1.src
x86_64:
tcpdump-debuginfo-4.9.2-4.24.amzn1.x86_64
tcpdump-4.9.2-4.24.amzn1.x86_64