ALAS-2022-1641

Related Vulnerabilities: CVE-2019-15167  

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463. (CVE-2019-15167)

ALAS-2022-1641


Amazon Linux AMI Security Advisory: ALAS-2022-1641
Advisory Release Date: 2022-12-01 17:33 Pacific
Advisory Updated Date: 2022-12-10 00:46 Pacific
Severity: Medium
References: CVE-2019-15167 

Issue Overview:

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463. (CVE-2019-15167)


Affected Packages:

tcpdump


Issue Correction:
Run yum update tcpdump to update your system.

New Packages:
i686:
    tcpdump-4.9.2-4.24.amzn1.i686
    tcpdump-debuginfo-4.9.2-4.24.amzn1.i686

src:
    tcpdump-4.9.2-4.24.amzn1.src

x86_64:
    tcpdump-debuginfo-4.9.2-4.24.amzn1.x86_64
    tcpdump-4.9.2-4.24.amzn1.x86_64