Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2020-8037 (GCVE-0-2020-8037)
Vulnerability from cvelistv5
Published
2020-11-04 17:55
Modified
2024-09-16 20:27
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- memory overallocation error
Summary
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
References
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
The TCPdump Group | tcpdump |
Version: 4.9.3 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T09:48:25.625Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231" }, { "name": "[debian-lts-announce] 20201110 [SECURITY] [DLA 2444-1] tcpdump security update", "tags": [ "mailing-list", "x_refsource_MLIST", "x_transferred" ], "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html" }, { "name": "FEDORA-2020-fae2e1f2bc", "tags": [ "vendor-advisory", "x_refsource_FEDORA", "x_transferred" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWDBONZVLC6BAOR2KM376DJCM4H3FERV/" }, { "name": "FEDORA-2020-c5e78886d6", "tags": [ "vendor-advisory", "x_refsource_FEDORA", "x_transferred" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2MX34MJIUJQGL6CMEPLTKFOOOC3CJ4Z/" }, { "name": "20210427 APPLE-SA-2021-04-26-3 Security Update 2021-002 Catalina", "tags": [ "mailing-list", "x_refsource_FULLDISC", "x_transferred" ], "url": "http://seclists.org/fulldisclosure/2021/Apr/51" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://support.apple.com/kb/HT212325" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://support.apple.com/kb/HT212326" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://support.apple.com/kb/HT212327" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "tcpdump", "vendor": "The TCPdump Group", "versions": [ { "status": "affected", "version": "4.9.3" } ] } ], "credits": [ { "lang": "en", "value": "Hardik Shah" } ], "datePublic": "2020-04-21T00:00:00", "descriptions": [ { "lang": "en", "value": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory." } ], "problemTypes": [ { "descriptions": [ { "description": "memory overallocation error", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2021-09-23T19:30:45", "orgId": "cfdbb673-b408-4d03-89c1-c3d73ed80896", "shortName": "Tcpdump" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231" }, { "name": "[debian-lts-announce] 20201110 [SECURITY] [DLA 2444-1] tcpdump security update", "tags": [ "mailing-list", "x_refsource_MLIST" ], "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html" }, { "name": "FEDORA-2020-fae2e1f2bc", "tags": [ "vendor-advisory", "x_refsource_FEDORA" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWDBONZVLC6BAOR2KM376DJCM4H3FERV/" }, { "name": "FEDORA-2020-c5e78886d6", "tags": [ "vendor-advisory", "x_refsource_FEDORA" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2MX34MJIUJQGL6CMEPLTKFOOOC3CJ4Z/" }, { "name": "20210427 APPLE-SA-2021-04-26-3 Security Update 2021-002 Catalina", "tags": [ "mailing-list", "x_refsource_FULLDISC" ], "url": "http://seclists.org/fulldisclosure/2021/Apr/51" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://support.apple.com/kb/HT212325" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://support.apple.com/kb/HT212326" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://support.apple.com/kb/HT212327" } ], "title": "ppp decapsulator can be convinced to allocate a large amount of memory", "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "security@tcpdump.org", "DATE_PUBLIC": "2020-04-21T00:00:00.000Z", "ID": "CVE-2020-8037", "STATE": "PUBLIC", "TITLE": "ppp decapsulator can be convinced to allocate a large amount of memory" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "tcpdump", "version": { "version_data": [ { "version_value": "4.9.3" } ] } } ] }, "vendor_name": "The TCPdump Group" } ] } }, "credit": [ { "lang": "eng", "value": "Hardik Shah" } ], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "memory overallocation error" } ] } ] }, "references": { "reference_data": [ { "name": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231", "refsource": "MISC", "url": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231" }, { "name": "[debian-lts-announce] 20201110 [SECURITY] [DLA 2444-1] tcpdump security update", "refsource": "MLIST", "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html" }, { "name": "FEDORA-2020-fae2e1f2bc", "refsource": "FEDORA", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LWDBONZVLC6BAOR2KM376DJCM4H3FERV/" }, { "name": "FEDORA-2020-c5e78886d6", "refsource": "FEDORA", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F2MX34MJIUJQGL6CMEPLTKFOOOC3CJ4Z/" }, { "name": "20210427 APPLE-SA-2021-04-26-3 Security Update 2021-002 Catalina", "refsource": "FULLDISC", "url": "http://seclists.org/fulldisclosure/2021/Apr/51" }, { "name": "https://support.apple.com/kb/HT212325", "refsource": "CONFIRM", "url": "https://support.apple.com/kb/HT212325" }, { "name": "https://support.apple.com/kb/HT212326", "refsource": "CONFIRM", "url": "https://support.apple.com/kb/HT212326" }, { "name": "https://support.apple.com/kb/HT212327", "refsource": "CONFIRM", "url": "https://support.apple.com/kb/HT212327" } ] } } } }, "cveMetadata": { "assignerOrgId": "cfdbb673-b408-4d03-89c1-c3d73ed80896", "assignerShortName": "Tcpdump", "cveId": "CVE-2020-8037", "datePublished": "2020-11-04T17:55:21.657199Z", "dateReserved": "2020-01-27T00:00:00", "dateUpdated": "2024-09-16T20:27:55.571Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2020-8037\",\"sourceIdentifier\":\"security@tcpdump.org\",\"published\":\"2020-11-04T18:15:20.843\",\"lastModified\":\"2024-11-21T05:38:16.200\",\"vulnStatus\":\"Modified\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.\"},{\"lang\":\"es\",\"value\":\"El ppp decapsulator en tcpdump versi\u00f3n 4.9.3 puede ser convencido para que asigne una gran cantidad de memoria\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\",\"baseScore\":7.5,\"baseSeverity\":\"HIGH\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"NONE\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"HIGH\"},\"exploitabilityScore\":3.9,\"impactScore\":3.6}],\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:N/AC:L/Au:N/C:N/I:N/A:P\",\"baseScore\":5.0,\"accessVector\":\"NETWORK\",\"accessComplexity\":\"LOW\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"NONE\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"PARTIAL\"},\"baseSeverity\":\"MEDIUM\",\"exploitabilityScore\":10.0,\"impactScore\":2.9,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":false}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-770\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:tcpdump:tcpdump:4.9.3:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"50B2D924-9D76-425D-828F-222F74F9F7AF\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"DEECE5FC-CACF-4496-A3E7-164736409252\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"36D96259-24BD-44E2-96D9-78CE1D41F956\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"E460AA51-FCDA-46B9-AE97-E6676AA5E194\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*\",\"versionEndExcluding\":\"10.14.6\",\"matchCriteriaId\":\"B0E97851-4DFF-4852-A339-183331F4ACBC\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"10.15\",\"versionEndExcluding\":\"10.15.7\",\"matchCriteriaId\":\"DB8A73F8-3074-4B32-B9F6-343B6B1988C5\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.14.6:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"693E7DAE-BBF0-4D48-9F8A-20DDBD4AAC0C\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-001:*:*:*:*:*:*\",\"matchCriteriaId\":\"CFE26ECC-A2C2-4501-9950-510DE0E1BD86\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-002:*:*:*:*:*:*\",\"matchCriteriaId\":\"26108BEF-0847-4AB0-BD98-35344DFA7835\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-001:*:*:*:*:*:*\",\"matchCriteriaId\":\"0FD3467D-7679-479F-9C0B-A93F7CD0929D\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-002:*:*:*:*:*:*\",\"matchCriteriaId\":\"D4C6098E-EDBD-4A85-8282-B2E9D9333872\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-003:*:*:*:*:*:*\",\"matchCriteriaId\":\"518BB47B-DD76-4E8C-9F10-7EBC1E146191\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-004:*:*:*:*:*:*\",\"matchCriteriaId\":\"63940A55-D851-46EB-9668-D82BEFC1FE95\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-005:*:*:*:*:*:*\",\"matchCriteriaId\":\"68C7A97A-3801-44FA-96CA-10298FA39883\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-006:*:*:*:*:*:*\",\"matchCriteriaId\":\"6D69914D-46C7-4A0E-A075-C863C1692D33\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-007:*:*:*:*:*:*\",\"matchCriteriaId\":\"9CDB4476-B521-43E4-A129-8718A8E0A8CD\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2021-001:*:*:*:*:*:*\",\"matchCriteriaId\":\"9D072B77-BE3F-4A2E-B66A-E2C8DC3781E4\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"A654B8A2-FC30-4171-B0BB-366CD7ED4B6A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:*\",\"matchCriteriaId\":\"F1F4BF7F-90D4-4668-B4E6-B06F4070F448\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-001:*:*:*:*:*:*\",\"matchCriteriaId\":\"0F441A43-1669-478D-9EC8-E96882DE4F9F\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:10.15.7:supplemental_update:*:*:*:*:*:*\",\"matchCriteriaId\":\"C1C795B9-E58D-467C-83A8-2D45C792292F\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"11.0\",\"versionEndExcluding\":\"11.3\",\"matchCriteriaId\":\"4E699CCC-31F5-458E-A59C-79B3AF143747\"}]}]}],\"references\":[{\"url\":\"http://seclists.org/fulldisclosure/2021/Apr/51\",\"source\":\"security@tcpdump.org\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231\",\"source\":\"security@tcpdump.org\",\"tags\":[\"Patch\",\"Third Party Advisory\"]},{\"url\":\"https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html\",\"source\":\"security@tcpdump.org\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2MX34MJIUJQGL6CMEPLTKFOOOC3CJ4Z/\",\"source\":\"security@tcpdump.org\"},{\"url\":\"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWDBONZVLC6BAOR2KM376DJCM4H3FERV/\",\"source\":\"security@tcpdump.org\"},{\"url\":\"https://support.apple.com/kb/HT212325\",\"source\":\"security@tcpdump.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://support.apple.com/kb/HT212326\",\"source\":\"security@tcpdump.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://support.apple.com/kb/HT212327\",\"source\":\"security@tcpdump.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://seclists.org/fulldisclosure/2021/Apr/51\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\",\"Third Party Advisory\"]},{\"url\":\"https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2MX34MJIUJQGL6CMEPLTKFOOOC3CJ4Z/\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWDBONZVLC6BAOR2KM376DJCM4H3FERV/\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://support.apple.com/kb/HT212325\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://support.apple.com/kb/HT212326\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://support.apple.com/kb/HT212327\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]}]}}" } }
rhsa-2021:4236
Vulnerability from csaf_redhat
Published
2021-11-09 18:45
Modified
2024-11-22 17:06
Summary
Red Hat Security Advisory: tcpdump security and bug fix update
Notes
Topic
An update for tcpdump is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Details
The tcpdump packages contain the tcpdump utility for monitoring network traffic. The tcpdump utility can capture and display the packet headers on a particular network interface or on all interfaces.
Security Fix(es):
* tcpdump: ppp decapsulator can be convinced to allocate a large amount of memory (CVE-2020-8037)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section.
Terms of Use
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
{ "document": { "aggregate_severity": { "namespace": "https://access.redhat.com/security/updates/classification/", "text": "Low" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "An update for tcpdump is now available for Red Hat Enterprise Linux 8.\n\nRed Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.", "title": "Topic" }, { "category": "general", "text": "The tcpdump packages contain the tcpdump utility for monitoring network traffic. The tcpdump utility can capture and display the packet headers on a particular network interface or on all interfaces.\n\nSecurity Fix(es):\n\n* tcpdump: ppp decapsulator can be convinced to allocate a large amount of memory (CVE-2020-8037)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section.", "title": "Details" }, { "category": "legal_disclaimer", "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.", "title": "Terms of Use" } ], "publisher": { "category": "vendor", "contact_details": "https://access.redhat.com/security/team/contact/", "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.", "name": "Red Hat Product Security", "namespace": "https://www.redhat.com" }, "references": [ { "category": "self", "summary": "https://access.redhat.com/errata/RHSA-2021:4236", "url": "https://access.redhat.com/errata/RHSA-2021:4236" }, { "category": "external", "summary": "https://access.redhat.com/security/updates/classification/#low", "url": "https://access.redhat.com/security/updates/classification/#low" }, { "category": "external", "summary": "https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.5_release_notes/", "url": "https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.5_release_notes/" }, { "category": "external", "summary": "1860216", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1860216" }, { "category": "external", "summary": "1895080", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1895080" }, { "category": "self", "summary": "Canonical URL", "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_4236.json" } ], "title": "Red Hat Security Advisory: tcpdump security and bug fix update", "tracking": { "current_release_date": "2024-11-22T17:06:36+00:00", "generator": { "date": "2024-11-22T17:06:36+00:00", "engine": { "name": "Red Hat SDEngine", "version": "4.2.1" } }, "id": "RHSA-2021:4236", "initial_release_date": "2021-11-09T18:45:55+00:00", "revision_history": [ { "date": "2021-11-09T18:45:55+00:00", "number": "1", "summary": "Initial version" }, { "date": "2021-11-09T18:45:55+00:00", "number": "2", "summary": "Last updated version" }, { "date": "2024-11-22T17:06:36+00:00", "number": "3", "summary": "Last generated version" } ], "status": "final", "version": "3" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_name", "name": "Red Hat Enterprise Linux AppStream (v. 8)", "product": { "name": "Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA", "product_identification_helper": { "cpe": "cpe:/a:redhat:enterprise_linux:8::appstream" } } } ], "category": "product_family", "name": "Red Hat Enterprise Linux" }, { "branches": [ { "category": "product_version", "name": "tcpdump-14:4.9.3-2.el8.src", "product": { "name": "tcpdump-14:4.9.3-2.el8.src", "product_id": "tcpdump-14:4.9.3-2.el8.src", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump@4.9.3-2.el8?arch=src\u0026epoch=14" } } } ], "category": "architecture", "name": "src" }, { "branches": [ { "category": "product_version", "name": "tcpdump-14:4.9.3-2.el8.aarch64", "product": { "name": "tcpdump-14:4.9.3-2.el8.aarch64", "product_id": "tcpdump-14:4.9.3-2.el8.aarch64", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump@4.9.3-2.el8?arch=aarch64\u0026epoch=14" } } }, { "category": "product_version", "name": "tcpdump-debugsource-14:4.9.3-2.el8.aarch64", "product": { "name": "tcpdump-debugsource-14:4.9.3-2.el8.aarch64", "product_id": "tcpdump-debugsource-14:4.9.3-2.el8.aarch64", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump-debugsource@4.9.3-2.el8?arch=aarch64\u0026epoch=14" } } }, { "category": "product_version", "name": "tcpdump-debuginfo-14:4.9.3-2.el8.aarch64", "product": { "name": "tcpdump-debuginfo-14:4.9.3-2.el8.aarch64", "product_id": "tcpdump-debuginfo-14:4.9.3-2.el8.aarch64", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump-debuginfo@4.9.3-2.el8?arch=aarch64\u0026epoch=14" } } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "tcpdump-14:4.9.3-2.el8.ppc64le", "product": { "name": "tcpdump-14:4.9.3-2.el8.ppc64le", "product_id": "tcpdump-14:4.9.3-2.el8.ppc64le", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump@4.9.3-2.el8?arch=ppc64le\u0026epoch=14" } } }, { "category": "product_version", "name": "tcpdump-debugsource-14:4.9.3-2.el8.ppc64le", "product": { "name": "tcpdump-debugsource-14:4.9.3-2.el8.ppc64le", "product_id": "tcpdump-debugsource-14:4.9.3-2.el8.ppc64le", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump-debugsource@4.9.3-2.el8?arch=ppc64le\u0026epoch=14" } } }, { "category": "product_version", "name": "tcpdump-debuginfo-14:4.9.3-2.el8.ppc64le", "product": { "name": "tcpdump-debuginfo-14:4.9.3-2.el8.ppc64le", "product_id": "tcpdump-debuginfo-14:4.9.3-2.el8.ppc64le", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump-debuginfo@4.9.3-2.el8?arch=ppc64le\u0026epoch=14" } } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "tcpdump-14:4.9.3-2.el8.x86_64", "product": { "name": "tcpdump-14:4.9.3-2.el8.x86_64", "product_id": "tcpdump-14:4.9.3-2.el8.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump@4.9.3-2.el8?arch=x86_64\u0026epoch=14" } } }, { "category": "product_version", "name": "tcpdump-debugsource-14:4.9.3-2.el8.x86_64", "product": { "name": "tcpdump-debugsource-14:4.9.3-2.el8.x86_64", "product_id": "tcpdump-debugsource-14:4.9.3-2.el8.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump-debugsource@4.9.3-2.el8?arch=x86_64\u0026epoch=14" } } }, { "category": "product_version", "name": "tcpdump-debuginfo-14:4.9.3-2.el8.x86_64", "product": { "name": "tcpdump-debuginfo-14:4.9.3-2.el8.x86_64", "product_id": "tcpdump-debuginfo-14:4.9.3-2.el8.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump-debuginfo@4.9.3-2.el8?arch=x86_64\u0026epoch=14" } } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_version", "name": "tcpdump-14:4.9.3-2.el8.s390x", "product": { "name": "tcpdump-14:4.9.3-2.el8.s390x", "product_id": "tcpdump-14:4.9.3-2.el8.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump@4.9.3-2.el8?arch=s390x\u0026epoch=14" } } }, { "category": "product_version", "name": "tcpdump-debugsource-14:4.9.3-2.el8.s390x", "product": { "name": "tcpdump-debugsource-14:4.9.3-2.el8.s390x", "product_id": "tcpdump-debugsource-14:4.9.3-2.el8.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump-debugsource@4.9.3-2.el8?arch=s390x\u0026epoch=14" } } }, { "category": "product_version", "name": "tcpdump-debuginfo-14:4.9.3-2.el8.s390x", "product": { "name": "tcpdump-debuginfo-14:4.9.3-2.el8.s390x", "product_id": "tcpdump-debuginfo-14:4.9.3-2.el8.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/tcpdump-debuginfo@4.9.3-2.el8?arch=s390x\u0026epoch=14" } } } ], "category": "architecture", "name": "s390x" } ], "category": "vendor", "name": "Red Hat" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "tcpdump-14:4.9.3-2.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.aarch64" }, "product_reference": "tcpdump-14:4.9.3-2.el8.aarch64", "relates_to_product_reference": "AppStream-8.5.0.GA" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-14:4.9.3-2.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.ppc64le" }, "product_reference": "tcpdump-14:4.9.3-2.el8.ppc64le", "relates_to_product_reference": "AppStream-8.5.0.GA" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-14:4.9.3-2.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.s390x" }, "product_reference": "tcpdump-14:4.9.3-2.el8.s390x", "relates_to_product_reference": "AppStream-8.5.0.GA" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-14:4.9.3-2.el8.src as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.src" }, "product_reference": "tcpdump-14:4.9.3-2.el8.src", "relates_to_product_reference": "AppStream-8.5.0.GA" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-14:4.9.3-2.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.x86_64" }, "product_reference": "tcpdump-14:4.9.3-2.el8.x86_64", "relates_to_product_reference": "AppStream-8.5.0.GA" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-debuginfo-14:4.9.3-2.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.aarch64" }, "product_reference": "tcpdump-debuginfo-14:4.9.3-2.el8.aarch64", "relates_to_product_reference": "AppStream-8.5.0.GA" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-debuginfo-14:4.9.3-2.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.ppc64le" }, "product_reference": "tcpdump-debuginfo-14:4.9.3-2.el8.ppc64le", "relates_to_product_reference": "AppStream-8.5.0.GA" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-debuginfo-14:4.9.3-2.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.s390x" }, "product_reference": "tcpdump-debuginfo-14:4.9.3-2.el8.s390x", "relates_to_product_reference": "AppStream-8.5.0.GA" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-debuginfo-14:4.9.3-2.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.x86_64" }, "product_reference": "tcpdump-debuginfo-14:4.9.3-2.el8.x86_64", "relates_to_product_reference": "AppStream-8.5.0.GA" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-debugsource-14:4.9.3-2.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.aarch64" }, "product_reference": "tcpdump-debugsource-14:4.9.3-2.el8.aarch64", "relates_to_product_reference": "AppStream-8.5.0.GA" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-debugsource-14:4.9.3-2.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.ppc64le" }, "product_reference": "tcpdump-debugsource-14:4.9.3-2.el8.ppc64le", "relates_to_product_reference": "AppStream-8.5.0.GA" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-debugsource-14:4.9.3-2.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.s390x" }, "product_reference": "tcpdump-debugsource-14:4.9.3-2.el8.s390x", "relates_to_product_reference": "AppStream-8.5.0.GA" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-debugsource-14:4.9.3-2.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)", "product_id": "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.x86_64" }, "product_reference": "tcpdump-debugsource-14:4.9.3-2.el8.x86_64", "relates_to_product_reference": "AppStream-8.5.0.GA" } ] }, "vulnerabilities": [ { "cve": "CVE-2020-8037", "cwe": { "id": "CWE-400", "name": "Uncontrolled Resource Consumption" }, "discovery_date": "2020-11-04T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1895080" } ], "notes": [ { "category": "description", "text": "A flaw was found in tcpdump while printing PPP packets captured in a pcap file or coming from the network. This flaw allows a remote attacker to send specially crafted packets that, when printed, can lead the application to allocate a large amount of memory, resulting in a denial of service. The highest threat from this vulnerability is to system availability.", "title": "Vulnerability description" }, { "category": "summary", "text": "tcpdump: ppp decapsulator can be convinced to allocate a large amount of memory", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.aarch64", "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.ppc64le", "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.s390x", "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.src", "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.x86_64", "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.aarch64", "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.ppc64le", "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.s390x", "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.x86_64", "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.aarch64", "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.ppc64le", "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.s390x", "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2020-8037" }, { "category": "external", "summary": "RHBZ#1895080", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1895080" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2020-8037", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8037" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2020-8037", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-8037" } ], "release_date": "2020-04-20T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2021-11-09T18:45:55+00:00", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258", "product_ids": [ "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.aarch64", "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.ppc64le", "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.s390x", "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.src", "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.x86_64", "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.aarch64", "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.ppc64le", "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.s390x", "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.x86_64", "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.aarch64", "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.ppc64le", "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.s390x", "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2021:4236" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.aarch64", "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.ppc64le", "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.s390x", "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.src", "AppStream-8.5.0.GA:tcpdump-14:4.9.3-2.el8.x86_64", "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.aarch64", "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.ppc64le", "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.s390x", "AppStream-8.5.0.GA:tcpdump-debuginfo-14:4.9.3-2.el8.x86_64", "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.aarch64", "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.ppc64le", "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.s390x", "AppStream-8.5.0.GA:tcpdump-debugsource-14:4.9.3-2.el8.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Low" } ], "title": "tcpdump: ppp decapsulator can be convinced to allocate a large amount of memory" } ] }
suse-su-2020:3358-1
Vulnerability from csaf_suse
Published
2020-11-17 12:17
Modified
2020-11-17 12:17
Summary
Security update for tcpdump
Notes
Title of the patch
Security update for tcpdump
Description of the patch
This update for tcpdump fixes the following issues:
- CVE-2020-8037: Fixed an issue where PPP decapsulator did not allocate the right buffer size (bsc#1178466).
Patchnames
SUSE-2020-3358,SUSE-SLE-Module-Basesystem-15-SP1-2020-3358,SUSE-SLE-Module-Basesystem-15-SP2-2020-3358
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for tcpdump", "title": "Title of the patch" }, { "category": "description", "text": "This update for tcpdump fixes the following issues:\n\n- CVE-2020-8037: Fixed an issue where PPP decapsulator did not allocate the right buffer size (bsc#1178466).\n", "title": "Description of the patch" }, { "category": "details", "text": "SUSE-2020-3358,SUSE-SLE-Module-Basesystem-15-SP1-2020-3358,SUSE-SLE-Module-Basesystem-15-SP2-2020-3358", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2020_3358-1.json" }, { "category": "self", "summary": "URL for SUSE-SU-2020:3358-1", "url": "https://www.suse.com/support/update/announcement/2020/suse-su-20203358-1/" }, { "category": "self", "summary": "E-Mail link for SUSE-SU-2020:3358-1", "url": "https://lists.suse.com/pipermail/sle-security-updates/2020-November/007789.html" }, { "category": "self", "summary": "SUSE Bug 1178466", "url": "https://bugzilla.suse.com/1178466" }, { "category": "self", "summary": "SUSE CVE CVE-2020-8037 page", "url": "https://www.suse.com/security/cve/CVE-2020-8037/" } ], "title": "Security update for tcpdump", "tracking": { "current_release_date": "2020-11-17T12:17:22Z", "generator": { "date": "2020-11-17T12:17:22Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "SUSE-SU-2020:3358-1", "initial_release_date": "2020-11-17T12:17:22Z", "revision_history": [ { "date": "2020-11-17T12:17:22Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-3.12.1.aarch64", "product": { "name": "tcpdump-4.9.2-3.12.1.aarch64", "product_id": "tcpdump-4.9.2-3.12.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-3.12.1.i586", "product": { "name": "tcpdump-4.9.2-3.12.1.i586", "product_id": "tcpdump-4.9.2-3.12.1.i586" } } ], "category": "architecture", "name": "i586" }, { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-3.12.1.ppc64le", "product": { "name": "tcpdump-4.9.2-3.12.1.ppc64le", "product_id": "tcpdump-4.9.2-3.12.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-3.12.1.s390x", "product": { "name": "tcpdump-4.9.2-3.12.1.s390x", "product_id": "tcpdump-4.9.2-3.12.1.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-3.12.1.x86_64", "product": { "name": "tcpdump-4.9.2-3.12.1.x86_64", "product_id": "tcpdump-4.9.2-3.12.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Linux Enterprise Module for Basesystem 15 SP1", "product": { "name": "SUSE Linux Enterprise Module for Basesystem 15 SP1", "product_id": "SUSE Linux Enterprise Module for Basesystem 15 SP1", "product_identification_helper": { "cpe": "cpe:/o:suse:sle-module-basesystem:15:sp1" } } }, { "category": "product_name", "name": "SUSE Linux Enterprise Module for Basesystem 15 SP2", "product": { "name": "SUSE Linux Enterprise Module for Basesystem 15 SP2", "product_id": "SUSE Linux Enterprise Module for Basesystem 15 SP2", "product_identification_helper": { "cpe": "cpe:/o:suse:sle-module-basesystem:15:sp2" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-3.12.1.aarch64 as component of SUSE Linux Enterprise Module for Basesystem 15 SP1", "product_id": "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.aarch64" }, "product_reference": "tcpdump-4.9.2-3.12.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Basesystem 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-3.12.1.ppc64le as component of SUSE Linux Enterprise Module for Basesystem 15 SP1", "product_id": "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.ppc64le" }, "product_reference": "tcpdump-4.9.2-3.12.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Module for Basesystem 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-3.12.1.s390x as component of SUSE Linux Enterprise Module for Basesystem 15 SP1", "product_id": "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.s390x" }, "product_reference": "tcpdump-4.9.2-3.12.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Module for Basesystem 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-3.12.1.x86_64 as component of SUSE Linux Enterprise Module for Basesystem 15 SP1", "product_id": "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.x86_64" }, "product_reference": "tcpdump-4.9.2-3.12.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Basesystem 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-3.12.1.aarch64 as component of SUSE Linux Enterprise Module for Basesystem 15 SP2", "product_id": "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.aarch64" }, "product_reference": "tcpdump-4.9.2-3.12.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Basesystem 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-3.12.1.ppc64le as component of SUSE Linux Enterprise Module for Basesystem 15 SP2", "product_id": "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.ppc64le" }, "product_reference": "tcpdump-4.9.2-3.12.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Module for Basesystem 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-3.12.1.s390x as component of SUSE Linux Enterprise Module for Basesystem 15 SP2", "product_id": "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.s390x" }, "product_reference": "tcpdump-4.9.2-3.12.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Module for Basesystem 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-3.12.1.x86_64 as component of SUSE Linux Enterprise Module for Basesystem 15 SP2", "product_id": "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.x86_64" }, "product_reference": "tcpdump-4.9.2-3.12.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Basesystem 15 SP2" } ] }, "vulnerabilities": [ { "cve": "CVE-2020-8037", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-8037" } ], "notes": [ { "category": "general", "text": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.aarch64", "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.ppc64le", "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.s390x", "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.x86_64", "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.aarch64", "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.ppc64le", "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.s390x", "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-8037", "url": "https://www.suse.com/security/cve/CVE-2020-8037" }, { "category": "external", "summary": "SUSE Bug 1178466 for CVE-2020-8037", "url": "https://bugzilla.suse.com/1178466" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.aarch64", "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.ppc64le", "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.s390x", "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.x86_64", "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.aarch64", "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.ppc64le", "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.s390x", "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.aarch64", "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.ppc64le", "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.s390x", "SUSE Linux Enterprise Module for Basesystem 15 SP1:tcpdump-4.9.2-3.12.1.x86_64", "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.aarch64", "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.ppc64le", "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.s390x", "SUSE Linux Enterprise Module for Basesystem 15 SP2:tcpdump-4.9.2-3.12.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:17:22Z", "details": "moderate" } ], "title": "CVE-2020-8037" } ] }
suse-su-2020:3360-1
Vulnerability from csaf_suse
Published
2020-11-17 12:41
Modified
2020-11-17 12:41
Summary
Security update for tcpdump
Notes
Title of the patch
Security update for tcpdump
Description of the patch
This update for tcpdump fixes the following issues:
- CVE-2020-8037: Fixed an issue where PPP decapsulator did not allocate the right buffer size (bsc#1178466).
The previous update of tcpdump already fixed variuous Buffer overflow/overread vulnerabilities [bsc#1153098, bsc#1153332]
- CVE-2017-16808 (AoE)
- CVE-2018-14468 (FrameRelay)
- CVE-2018-14469 (IKEv1)
- CVE-2018-14470 (BABEL)
- CVE-2018-14466 (AFS/RX)
- CVE-2018-14461 (LDP)
- CVE-2018-14462 (ICMP)
- CVE-2018-14465 (RSVP)
- CVE-2018-14464 (LMP)
- CVE-2019-15166 (LMP)
- CVE-2018-14880 (OSPF6)
- CVE-2018-14882 (RPL)
- CVE-2018-16227 (802.11)
- CVE-2018-16229 (DCCP)
- CVE-2018-14467 (BGP)
- CVE-2018-14881 (BGP)
- CVE-2018-16230 (BGP)
- CVE-2018-16300 (BGP)
- CVE-2018-14463 (VRRP)
- CVE-2019-15167 (VRRP)
- CVE-2018-14879 (tcpdump -V)
- CVE-2018-16228 (HNCP) is a duplicate of the already fixed CVE-2019-1010220
- CVE-2018-16301 (fixed in libpcap)
- CVE-2018-16451 (SMB)
- CVE-2018-16452 (SMB)
- CVE-2018-10103 (SMB - partially fixed, but SMB printing disabled)
- CVE-2018-10105 (SMB - too unreliably reproduced, SMB printing disabled)
Patchnames
SUSE-2020-3360,SUSE-SLE-SERVER-12-SP5-2020-3360
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for tcpdump", "title": "Title of the patch" }, { "category": "description", "text": "This update for tcpdump fixes the following issues:\n\n- CVE-2020-8037: Fixed an issue where PPP decapsulator did not allocate the right buffer size (bsc#1178466).\n\nThe previous update of tcpdump already fixed variuous Buffer overflow/overread vulnerabilities [bsc#1153098, bsc#1153332]\n\n- CVE-2017-16808 (AoE)\n- CVE-2018-14468 (FrameRelay)\n- CVE-2018-14469 (IKEv1)\n- CVE-2018-14470 (BABEL)\n- CVE-2018-14466 (AFS/RX)\n- CVE-2018-14461 (LDP)\n- CVE-2018-14462 (ICMP)\n- CVE-2018-14465 (RSVP)\n- CVE-2018-14464 (LMP)\n- CVE-2019-15166 (LMP)\n- CVE-2018-14880 (OSPF6)\n- CVE-2018-14882 (RPL)\n- CVE-2018-16227 (802.11)\n- CVE-2018-16229 (DCCP)\n- CVE-2018-14467 (BGP)\n- CVE-2018-14881 (BGP)\n- CVE-2018-16230 (BGP)\n- CVE-2018-16300 (BGP)\n- CVE-2018-14463 (VRRP)\n- CVE-2019-15167 (VRRP)\n- CVE-2018-14879 (tcpdump -V)\n- CVE-2018-16228 (HNCP) is a duplicate of the already fixed CVE-2019-1010220\n- CVE-2018-16301 (fixed in libpcap)\n- CVE-2018-16451 (SMB)\n- CVE-2018-16452 (SMB)\n- CVE-2018-10103 (SMB - partially fixed, but SMB printing disabled)\n- CVE-2018-10105 (SMB - too unreliably reproduced, SMB printing disabled)\n", "title": "Description of the patch" }, { "category": "details", "text": "SUSE-2020-3360,SUSE-SLE-SERVER-12-SP5-2020-3360", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2020_3360-1.json" }, { "category": "self", "summary": "URL for SUSE-SU-2020:3360-1", "url": "https://www.suse.com/support/update/announcement/2020/suse-su-20203360-1/" }, { "category": "self", "summary": "E-Mail link for SUSE-SU-2020:3360-1", "url": "https://lists.suse.com/pipermail/sle-security-updates/2020-November/007788.html" }, { "category": "self", "summary": "SUSE Bug 1153098", "url": "https://bugzilla.suse.com/1153098" }, { "category": "self", "summary": "SUSE Bug 1153332", "url": "https://bugzilla.suse.com/1153332" }, { "category": "self", "summary": "SUSE Bug 1178466", "url": "https://bugzilla.suse.com/1178466" }, { "category": "self", "summary": "SUSE CVE CVE-2017-16808 page", "url": "https://www.suse.com/security/cve/CVE-2017-16808/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-10103 page", "url": "https://www.suse.com/security/cve/CVE-2018-10103/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-10105 page", "url": "https://www.suse.com/security/cve/CVE-2018-10105/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14461 page", "url": "https://www.suse.com/security/cve/CVE-2018-14461/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14462 page", "url": "https://www.suse.com/security/cve/CVE-2018-14462/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14463 page", "url": "https://www.suse.com/security/cve/CVE-2018-14463/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14464 page", "url": "https://www.suse.com/security/cve/CVE-2018-14464/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14465 page", "url": "https://www.suse.com/security/cve/CVE-2018-14465/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14466 page", "url": "https://www.suse.com/security/cve/CVE-2018-14466/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14467 page", "url": "https://www.suse.com/security/cve/CVE-2018-14467/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14468 page", "url": "https://www.suse.com/security/cve/CVE-2018-14468/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14469 page", "url": "https://www.suse.com/security/cve/CVE-2018-14469/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14470 page", "url": "https://www.suse.com/security/cve/CVE-2018-14470/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14879 page", "url": "https://www.suse.com/security/cve/CVE-2018-14879/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14880 page", "url": "https://www.suse.com/security/cve/CVE-2018-14880/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14881 page", "url": "https://www.suse.com/security/cve/CVE-2018-14881/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14882 page", "url": "https://www.suse.com/security/cve/CVE-2018-14882/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16227 page", "url": "https://www.suse.com/security/cve/CVE-2018-16227/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16228 page", "url": "https://www.suse.com/security/cve/CVE-2018-16228/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16229 page", "url": "https://www.suse.com/security/cve/CVE-2018-16229/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16230 page", "url": "https://www.suse.com/security/cve/CVE-2018-16230/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16300 page", "url": "https://www.suse.com/security/cve/CVE-2018-16300/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16301 page", "url": "https://www.suse.com/security/cve/CVE-2018-16301/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16451 page", "url": "https://www.suse.com/security/cve/CVE-2018-16451/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16452 page", "url": "https://www.suse.com/security/cve/CVE-2018-16452/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1010220 page", "url": "https://www.suse.com/security/cve/CVE-2019-1010220/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-15166 page", "url": "https://www.suse.com/security/cve/CVE-2019-15166/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-15167 page", "url": "https://www.suse.com/security/cve/CVE-2019-15167/" }, { "category": "self", "summary": "SUSE CVE CVE-2020-8037 page", "url": "https://www.suse.com/security/cve/CVE-2020-8037/" } ], "title": "Security update for tcpdump", "tracking": { "current_release_date": "2020-11-17T12:41:00Z", "generator": { "date": "2020-11-17T12:41:00Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "SUSE-SU-2020:3360-1", "initial_release_date": "2020-11-17T12:41:00Z", "revision_history": [ { "date": "2020-11-17T12:41:00Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-14.17.1.aarch64", "product": { "name": "tcpdump-4.9.2-14.17.1.aarch64", "product_id": "tcpdump-4.9.2-14.17.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-14.17.1.i586", "product": { "name": "tcpdump-4.9.2-14.17.1.i586", "product_id": "tcpdump-4.9.2-14.17.1.i586" } } ], "category": "architecture", "name": "i586" }, { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-14.17.1.ppc64le", "product": { "name": "tcpdump-4.9.2-14.17.1.ppc64le", "product_id": "tcpdump-4.9.2-14.17.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-14.17.1.s390", "product": { "name": "tcpdump-4.9.2-14.17.1.s390", "product_id": "tcpdump-4.9.2-14.17.1.s390" } } ], "category": "architecture", "name": "s390" }, { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-14.17.1.s390x", "product": { "name": "tcpdump-4.9.2-14.17.1.s390x", "product_id": "tcpdump-4.9.2-14.17.1.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-14.17.1.x86_64", "product": { "name": "tcpdump-4.9.2-14.17.1.x86_64", "product_id": "tcpdump-4.9.2-14.17.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Linux Enterprise Server 12 SP5", "product": { "name": "SUSE Linux Enterprise Server 12 SP5", "product_id": "SUSE Linux Enterprise Server 12 SP5", "product_identification_helper": { "cpe": "cpe:/o:suse:sles:12:sp5" } } }, { "category": "product_name", "name": "SUSE Linux Enterprise Server for SAP Applications 12 SP5", "product": { "name": "SUSE Linux Enterprise Server for SAP Applications 12 SP5", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12 SP5", "product_identification_helper": { "cpe": "cpe:/o:suse:sles_sap:12:sp5" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-14.17.1.aarch64 as component of SUSE Linux Enterprise Server 12 SP5", "product_id": "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64" }, "product_reference": "tcpdump-4.9.2-14.17.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12 SP5" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-14.17.1.ppc64le as component of SUSE Linux Enterprise Server 12 SP5", "product_id": "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le" }, "product_reference": "tcpdump-4.9.2-14.17.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12 SP5" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-14.17.1.s390x as component of SUSE Linux Enterprise Server 12 SP5", "product_id": "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x" }, "product_reference": "tcpdump-4.9.2-14.17.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12 SP5" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-14.17.1.x86_64 as component of SUSE Linux Enterprise Server 12 SP5", "product_id": "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" }, "product_reference": "tcpdump-4.9.2-14.17.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12 SP5" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-14.17.1.aarch64 as component of SUSE Linux Enterprise Server for SAP Applications 12 SP5", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64" }, "product_reference": "tcpdump-4.9.2-14.17.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12 SP5" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-14.17.1.ppc64le as component of SUSE Linux Enterprise Server for SAP Applications 12 SP5", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le" }, "product_reference": "tcpdump-4.9.2-14.17.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12 SP5" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-14.17.1.s390x as component of SUSE Linux Enterprise Server for SAP Applications 12 SP5", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x" }, "product_reference": "tcpdump-4.9.2-14.17.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12 SP5" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-14.17.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12 SP5", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" }, "product_reference": "tcpdump-4.9.2-14.17.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12 SP5" } ] }, "vulnerabilities": [ { "cve": "CVE-2017-16808", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-16808" } ], "notes": [ { "category": "general", "text": "tcpdump before 4.9.3 has a heap-based buffer over-read related to aoe_print in print-aoe.c and lookup_emem in addrtoname.c.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-16808", "url": "https://www.suse.com/security/cve/CVE-2017-16808" }, { "category": "external", "summary": "SUSE Bug 1068716 for CVE-2017-16808", "url": "https://bugzilla.suse.com/1068716" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2017-16808", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "important" } ], "title": "CVE-2017-16808" }, { "cve": "CVE-2018-10103", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-10103" } ], "notes": [ { "category": "general", "text": "tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-10103", "url": "https://www.suse.com/security/cve/CVE-2018-10103" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-10103", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-10103" }, { "cve": "CVE-2018-10105", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-10105" } ], "notes": [ { "category": "general", "text": "tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-10105", "url": "https://www.suse.com/security/cve/CVE-2018-10105" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-10105", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-10105" }, { "cve": "CVE-2018-14461", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14461" } ], "notes": [ { "category": "general", "text": "The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14461", "url": "https://www.suse.com/security/cve/CVE-2018-14461" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14461", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14461" }, { "cve": "CVE-2018-14462", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14462" } ], "notes": [ { "category": "general", "text": "The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14462", "url": "https://www.suse.com/security/cve/CVE-2018-14462" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14462", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14462" }, { "cve": "CVE-2018-14463", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14463" } ], "notes": [ { "category": "general", "text": "The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14463", "url": "https://www.suse.com/security/cve/CVE-2018-14463" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14463", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14463" }, { "cve": "CVE-2018-14464", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14464" } ], "notes": [ { "category": "general", "text": "The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14464", "url": "https://www.suse.com/security/cve/CVE-2018-14464" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14464", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14464" }, { "cve": "CVE-2018-14465", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14465" } ], "notes": [ { "category": "general", "text": "The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14465", "url": "https://www.suse.com/security/cve/CVE-2018-14465" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14465", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14465" }, { "cve": "CVE-2018-14466", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14466" } ], "notes": [ { "category": "general", "text": "The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14466", "url": "https://www.suse.com/security/cve/CVE-2018-14466" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14466", "url": "https://bugzilla.suse.com/1153098" }, { "category": "external", "summary": "SUSE Bug 1166972 for CVE-2018-14466", "url": "https://bugzilla.suse.com/1166972" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14466" }, { "cve": "CVE-2018-14467", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14467" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14467", "url": "https://www.suse.com/security/cve/CVE-2018-14467" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14467", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14467" }, { "cve": "CVE-2018-14468", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14468" } ], "notes": [ { "category": "general", "text": "The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14468", "url": "https://www.suse.com/security/cve/CVE-2018-14468" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14468", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14468" }, { "cve": "CVE-2018-14469", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14469" } ], "notes": [ { "category": "general", "text": "The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14469", "url": "https://www.suse.com/security/cve/CVE-2018-14469" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14469", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14469" }, { "cve": "CVE-2018-14470", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14470" } ], "notes": [ { "category": "general", "text": "The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14470", "url": "https://www.suse.com/security/cve/CVE-2018-14470" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14470", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14470" }, { "cve": "CVE-2018-14879", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14879" } ], "notes": [ { "category": "general", "text": "The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14879", "url": "https://www.suse.com/security/cve/CVE-2018-14879" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14879", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 0, "baseSeverity": "NONE", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "low" } ], "title": "CVE-2018-14879" }, { "cve": "CVE-2018-14880", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14880" } ], "notes": [ { "category": "general", "text": "The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14880", "url": "https://www.suse.com/security/cve/CVE-2018-14880" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14880", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14880" }, { "cve": "CVE-2018-14881", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14881" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14881", "url": "https://www.suse.com/security/cve/CVE-2018-14881" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14881", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14881" }, { "cve": "CVE-2018-14882", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14882" } ], "notes": [ { "category": "general", "text": "The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14882", "url": "https://www.suse.com/security/cve/CVE-2018-14882" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14882", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-14882" }, { "cve": "CVE-2018-16227", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16227" } ], "notes": [ { "category": "general", "text": "The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16227", "url": "https://www.suse.com/security/cve/CVE-2018-16227" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16227", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-16227" }, { "cve": "CVE-2018-16228", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16228" } ], "notes": [ { "category": "general", "text": "The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16228", "url": "https://www.suse.com/security/cve/CVE-2018-16228" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16228", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-16228" }, { "cve": "CVE-2018-16229", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16229" } ], "notes": [ { "category": "general", "text": "The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16229", "url": "https://www.suse.com/security/cve/CVE-2018-16229" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16229", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-16229" }, { "cve": "CVE-2018-16230", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16230" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16230", "url": "https://www.suse.com/security/cve/CVE-2018-16230" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16230", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-16230" }, { "cve": "CVE-2018-16300", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16300" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16300", "url": "https://www.suse.com/security/cve/CVE-2018-16300" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16300", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "important" } ], "title": "CVE-2018-16300" }, { "cve": "CVE-2018-16301", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16301" } ], "notes": [ { "category": "general", "text": "The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16301", "url": "https://www.suse.com/security/cve/CVE-2018-16301" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16301", "url": "https://bugzilla.suse.com/1153098" }, { "category": "external", "summary": "SUSE Bug 1153332 for CVE-2018-16301", "url": "https://bugzilla.suse.com/1153332" }, { "category": "external", "summary": "SUSE Bug 1195825 for CVE-2018-16301", "url": "https://bugzilla.suse.com/1195825" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "important" } ], "title": "CVE-2018-16301" }, { "cve": "CVE-2018-16451", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16451" } ], "notes": [ { "category": "general", "text": "The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \\MAILSLOT\\BROWSE and \\PIPE\\LANMAN.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16451", "url": "https://www.suse.com/security/cve/CVE-2018-16451" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16451", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-16451" }, { "cve": "CVE-2018-16452", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16452" } ], "notes": [ { "category": "general", "text": "The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16452", "url": "https://www.suse.com/security/cve/CVE-2018-16452" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16452", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2018-16452" }, { "cve": "CVE-2019-1010220", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1010220" } ], "notes": [ { "category": "general", "text": "tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: \"ND_PRINT((ndo, \"%s\", buf));\", in function named \"print_prefix\", in \"print-hncp.c\". The attack vector is: The victim must open a specially crafted pcap file.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1010220", "url": "https://www.suse.com/security/cve/CVE-2019-1010220" }, { "category": "external", "summary": "SUSE Bug 1142439 for CVE-2019-1010220", "url": "https://bugzilla.suse.com/1142439" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2019-1010220", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2019-1010220" }, { "cve": "CVE-2019-15166", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-15166" } ], "notes": [ { "category": "general", "text": "lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-15166", "url": "https://www.suse.com/security/cve/CVE-2019-15166" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2019-15166", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2019-15166" }, { "cve": "CVE-2019-15167", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-15167" } ], "notes": [ { "category": "general", "text": "The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-15167", "url": "https://www.suse.com/security/cve/CVE-2019-15167" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2019-15167", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2019-15167" }, { "cve": "CVE-2020-8037", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-8037" } ], "notes": [ { "category": "general", "text": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-8037", "url": "https://www.suse.com/security/cve/CVE-2020-8037" }, { "category": "external", "summary": "SUSE Bug 1178466 for CVE-2020-8037", "url": "https://bugzilla.suse.com/1178466" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server 12 SP5:tcpdump-4.9.2-14.17.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.aarch64", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.ppc64le", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.s390x", "SUSE Linux Enterprise Server for SAP Applications 12 SP5:tcpdump-4.9.2-14.17.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-17T12:41:00Z", "details": "moderate" } ], "title": "CVE-2020-8037" } ] }
opensuse-su-2020:1983-1
Vulnerability from csaf_opensuse
Published
2020-11-20 17:24
Modified
2020-11-20 17:24
Summary
Security update for tcpdump
Notes
Title of the patch
Security update for tcpdump
Description of the patch
This update for tcpdump fixes the following issues:
- CVE-2020-8037: Fixed an issue where PPP decapsulator did not allocate the right buffer size (bsc#1178466).
This update was imported from the SUSE:SLE-15:Update update project.
Patchnames
openSUSE-2020-1983
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for tcpdump", "title": "Title of the patch" }, { "category": "description", "text": "This update for tcpdump fixes the following issues:\n\n- CVE-2020-8037: Fixed an issue where PPP decapsulator did not allocate the right buffer size (bsc#1178466).\n\nThis update was imported from the SUSE:SLE-15:Update update project.", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-2020-1983", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2020_1983-1.json" }, { "category": "self", "summary": "URL for openSUSE-SU-2020:1983-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LS4ETM3JSH2SWUOYCYLRBRPQPCJ7QXGX/" }, { "category": "self", "summary": "E-Mail link for openSUSE-SU-2020:1983-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LS4ETM3JSH2SWUOYCYLRBRPQPCJ7QXGX/" }, { "category": "self", "summary": "SUSE Bug 1178466", "url": "https://bugzilla.suse.com/1178466" }, { "category": "self", "summary": "SUSE CVE CVE-2020-8037 page", "url": "https://www.suse.com/security/cve/CVE-2020-8037/" } ], "title": "Security update for tcpdump", "tracking": { "current_release_date": "2020-11-20T17:24:10Z", "generator": { "date": "2020-11-20T17:24:10Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2020:1983-1", "initial_release_date": "2020-11-20T17:24:10Z", "revision_history": [ { "date": "2020-11-20T17:24:10Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-lp151.4.9.1.x86_64", "product": { "name": "tcpdump-4.9.2-lp151.4.9.1.x86_64", "product_id": "tcpdump-4.9.2-lp151.4.9.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "openSUSE Leap 15.1", "product": { "name": "openSUSE Leap 15.1", "product_id": "openSUSE Leap 15.1", "product_identification_helper": { "cpe": "cpe:/o:opensuse:leap:15.1" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-lp151.4.9.1.x86_64 as component of openSUSE Leap 15.1", "product_id": "openSUSE Leap 15.1:tcpdump-4.9.2-lp151.4.9.1.x86_64" }, "product_reference": "tcpdump-4.9.2-lp151.4.9.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.1" } ] }, "vulnerabilities": [ { "cve": "CVE-2020-8037", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-8037" } ], "notes": [ { "category": "general", "text": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Leap 15.1:tcpdump-4.9.2-lp151.4.9.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-8037", "url": "https://www.suse.com/security/cve/CVE-2020-8037" }, { "category": "external", "summary": "SUSE Bug 1178466 for CVE-2020-8037", "url": "https://bugzilla.suse.com/1178466" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Leap 15.1:tcpdump-4.9.2-lp151.4.9.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "openSUSE Leap 15.1:tcpdump-4.9.2-lp151.4.9.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-20T17:24:10Z", "details": "moderate" } ], "title": "CVE-2020-8037" } ] }
opensuse-su-2024:11425-1
Vulnerability from csaf_opensuse
Published
2024-06-15 00:00
Modified
2024-06-15 00:00
Summary
tcpdump-4.99.1-1.2 on GA media
Notes
Title of the patch
tcpdump-4.99.1-1.2 on GA media
Description of the patch
These are all security issues fixed in the tcpdump-4.99.1-1.2 package on the GA media of openSUSE Tumbleweed.
Patchnames
openSUSE-Tumbleweed-2024-11425
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "tcpdump-4.99.1-1.2 on GA media", "title": "Title of the patch" }, { "category": "description", "text": "These are all security issues fixed in the tcpdump-4.99.1-1.2 package on the GA media of openSUSE Tumbleweed.", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-Tumbleweed-2024-11425", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_11425-1.json" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7922 page", "url": "https://www.suse.com/security/cve/CVE-2016-7922/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7923 page", "url": "https://www.suse.com/security/cve/CVE-2016-7923/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7924 page", "url": "https://www.suse.com/security/cve/CVE-2016-7924/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7925 page", "url": "https://www.suse.com/security/cve/CVE-2016-7925/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7926 page", "url": "https://www.suse.com/security/cve/CVE-2016-7926/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7927 page", "url": "https://www.suse.com/security/cve/CVE-2016-7927/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7928 page", "url": "https://www.suse.com/security/cve/CVE-2016-7928/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7929 page", "url": "https://www.suse.com/security/cve/CVE-2016-7929/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7930 page", "url": "https://www.suse.com/security/cve/CVE-2016-7930/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7931 page", "url": "https://www.suse.com/security/cve/CVE-2016-7931/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7932 page", "url": "https://www.suse.com/security/cve/CVE-2016-7932/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7933 page", "url": "https://www.suse.com/security/cve/CVE-2016-7933/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7934 page", "url": "https://www.suse.com/security/cve/CVE-2016-7934/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7935 page", "url": "https://www.suse.com/security/cve/CVE-2016-7935/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7936 page", "url": "https://www.suse.com/security/cve/CVE-2016-7936/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7937 page", "url": "https://www.suse.com/security/cve/CVE-2016-7937/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7938 page", "url": "https://www.suse.com/security/cve/CVE-2016-7938/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7939 page", "url": "https://www.suse.com/security/cve/CVE-2016-7939/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7940 page", "url": "https://www.suse.com/security/cve/CVE-2016-7940/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7973 page", "url": "https://www.suse.com/security/cve/CVE-2016-7973/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7974 page", "url": "https://www.suse.com/security/cve/CVE-2016-7974/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7975 page", "url": "https://www.suse.com/security/cve/CVE-2016-7975/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7983 page", "url": "https://www.suse.com/security/cve/CVE-2016-7983/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7984 page", "url": "https://www.suse.com/security/cve/CVE-2016-7984/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7985 page", "url": "https://www.suse.com/security/cve/CVE-2016-7985/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7986 page", "url": "https://www.suse.com/security/cve/CVE-2016-7986/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7992 page", "url": "https://www.suse.com/security/cve/CVE-2016-7992/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7993 page", "url": "https://www.suse.com/security/cve/CVE-2016-7993/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-8574 page", "url": "https://www.suse.com/security/cve/CVE-2016-8574/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-8575 page", "url": "https://www.suse.com/security/cve/CVE-2016-8575/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-11108 page", "url": "https://www.suse.com/security/cve/CVE-2017-11108/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-11541 page", "url": "https://www.suse.com/security/cve/CVE-2017-11541/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-11542 page", "url": "https://www.suse.com/security/cve/CVE-2017-11542/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-11543 page", "url": "https://www.suse.com/security/cve/CVE-2017-11543/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12893 page", "url": "https://www.suse.com/security/cve/CVE-2017-12893/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12894 page", "url": "https://www.suse.com/security/cve/CVE-2017-12894/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12895 page", "url": "https://www.suse.com/security/cve/CVE-2017-12895/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12896 page", "url": "https://www.suse.com/security/cve/CVE-2017-12896/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12897 page", "url": "https://www.suse.com/security/cve/CVE-2017-12897/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12898 page", "url": "https://www.suse.com/security/cve/CVE-2017-12898/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12899 page", "url": "https://www.suse.com/security/cve/CVE-2017-12899/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12900 page", "url": "https://www.suse.com/security/cve/CVE-2017-12900/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12901 page", "url": "https://www.suse.com/security/cve/CVE-2017-12901/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12902 page", "url": "https://www.suse.com/security/cve/CVE-2017-12902/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12985 page", "url": "https://www.suse.com/security/cve/CVE-2017-12985/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12986 page", "url": "https://www.suse.com/security/cve/CVE-2017-12986/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12987 page", "url": "https://www.suse.com/security/cve/CVE-2017-12987/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12988 page", "url": "https://www.suse.com/security/cve/CVE-2017-12988/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12989 page", "url": "https://www.suse.com/security/cve/CVE-2017-12989/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12990 page", "url": "https://www.suse.com/security/cve/CVE-2017-12990/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12991 page", "url": "https://www.suse.com/security/cve/CVE-2017-12991/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12992 page", "url": "https://www.suse.com/security/cve/CVE-2017-12992/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12993 page", "url": "https://www.suse.com/security/cve/CVE-2017-12993/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12994 page", "url": "https://www.suse.com/security/cve/CVE-2017-12994/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12995 page", "url": "https://www.suse.com/security/cve/CVE-2017-12995/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12996 page", "url": "https://www.suse.com/security/cve/CVE-2017-12996/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12997 page", "url": "https://www.suse.com/security/cve/CVE-2017-12997/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12998 page", "url": "https://www.suse.com/security/cve/CVE-2017-12998/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-12999 page", "url": "https://www.suse.com/security/cve/CVE-2017-12999/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13000 page", "url": "https://www.suse.com/security/cve/CVE-2017-13000/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13001 page", "url": "https://www.suse.com/security/cve/CVE-2017-13001/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13002 page", "url": "https://www.suse.com/security/cve/CVE-2017-13002/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13003 page", "url": "https://www.suse.com/security/cve/CVE-2017-13003/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13004 page", "url": "https://www.suse.com/security/cve/CVE-2017-13004/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13005 page", "url": "https://www.suse.com/security/cve/CVE-2017-13005/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13006 page", "url": "https://www.suse.com/security/cve/CVE-2017-13006/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13007 page", "url": "https://www.suse.com/security/cve/CVE-2017-13007/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13008 page", "url": "https://www.suse.com/security/cve/CVE-2017-13008/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13009 page", "url": "https://www.suse.com/security/cve/CVE-2017-13009/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13010 page", "url": "https://www.suse.com/security/cve/CVE-2017-13010/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13011 page", "url": "https://www.suse.com/security/cve/CVE-2017-13011/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13012 page", "url": "https://www.suse.com/security/cve/CVE-2017-13012/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13013 page", "url": "https://www.suse.com/security/cve/CVE-2017-13013/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13014 page", "url": "https://www.suse.com/security/cve/CVE-2017-13014/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13015 page", "url": "https://www.suse.com/security/cve/CVE-2017-13015/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13016 page", "url": "https://www.suse.com/security/cve/CVE-2017-13016/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13017 page", "url": "https://www.suse.com/security/cve/CVE-2017-13017/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13018 page", "url": "https://www.suse.com/security/cve/CVE-2017-13018/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13019 page", "url": "https://www.suse.com/security/cve/CVE-2017-13019/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13020 page", "url": "https://www.suse.com/security/cve/CVE-2017-13020/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13021 page", "url": "https://www.suse.com/security/cve/CVE-2017-13021/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13022 page", "url": "https://www.suse.com/security/cve/CVE-2017-13022/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13023 page", "url": "https://www.suse.com/security/cve/CVE-2017-13023/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13024 page", "url": "https://www.suse.com/security/cve/CVE-2017-13024/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13025 page", "url": "https://www.suse.com/security/cve/CVE-2017-13025/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13026 page", "url": "https://www.suse.com/security/cve/CVE-2017-13026/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13027 page", "url": "https://www.suse.com/security/cve/CVE-2017-13027/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13028 page", "url": "https://www.suse.com/security/cve/CVE-2017-13028/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13029 page", "url": "https://www.suse.com/security/cve/CVE-2017-13029/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13030 page", "url": "https://www.suse.com/security/cve/CVE-2017-13030/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13031 page", "url": "https://www.suse.com/security/cve/CVE-2017-13031/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13032 page", "url": "https://www.suse.com/security/cve/CVE-2017-13032/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13033 page", "url": "https://www.suse.com/security/cve/CVE-2017-13033/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13034 page", "url": "https://www.suse.com/security/cve/CVE-2017-13034/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13035 page", "url": "https://www.suse.com/security/cve/CVE-2017-13035/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13036 page", "url": "https://www.suse.com/security/cve/CVE-2017-13036/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13037 page", "url": "https://www.suse.com/security/cve/CVE-2017-13037/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13038 page", "url": "https://www.suse.com/security/cve/CVE-2017-13038/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13039 page", "url": "https://www.suse.com/security/cve/CVE-2017-13039/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13040 page", "url": "https://www.suse.com/security/cve/CVE-2017-13040/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13041 page", "url": "https://www.suse.com/security/cve/CVE-2017-13041/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13042 page", "url": "https://www.suse.com/security/cve/CVE-2017-13042/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13043 page", "url": "https://www.suse.com/security/cve/CVE-2017-13043/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13044 page", "url": "https://www.suse.com/security/cve/CVE-2017-13044/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13045 page", "url": "https://www.suse.com/security/cve/CVE-2017-13045/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13046 page", "url": "https://www.suse.com/security/cve/CVE-2017-13046/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13047 page", "url": "https://www.suse.com/security/cve/CVE-2017-13047/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13048 page", "url": "https://www.suse.com/security/cve/CVE-2017-13048/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13049 page", "url": "https://www.suse.com/security/cve/CVE-2017-13049/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13050 page", "url": "https://www.suse.com/security/cve/CVE-2017-13050/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13051 page", "url": "https://www.suse.com/security/cve/CVE-2017-13051/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13052 page", "url": "https://www.suse.com/security/cve/CVE-2017-13052/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13053 page", "url": "https://www.suse.com/security/cve/CVE-2017-13053/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13054 page", "url": "https://www.suse.com/security/cve/CVE-2017-13054/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13055 page", "url": "https://www.suse.com/security/cve/CVE-2017-13055/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13687 page", "url": "https://www.suse.com/security/cve/CVE-2017-13687/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13688 page", "url": "https://www.suse.com/security/cve/CVE-2017-13688/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13689 page", "url": "https://www.suse.com/security/cve/CVE-2017-13689/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13690 page", "url": "https://www.suse.com/security/cve/CVE-2017-13690/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-13725 page", "url": "https://www.suse.com/security/cve/CVE-2017-13725/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-16808 page", "url": "https://www.suse.com/security/cve/CVE-2017-16808/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-5202 page", "url": "https://www.suse.com/security/cve/CVE-2017-5202/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-5203 page", "url": "https://www.suse.com/security/cve/CVE-2017-5203/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-5204 page", "url": "https://www.suse.com/security/cve/CVE-2017-5204/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-5205 page", "url": "https://www.suse.com/security/cve/CVE-2017-5205/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-5341 page", "url": "https://www.suse.com/security/cve/CVE-2017-5341/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-5342 page", "url": "https://www.suse.com/security/cve/CVE-2017-5342/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-5482 page", "url": "https://www.suse.com/security/cve/CVE-2017-5482/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-5483 page", "url": "https://www.suse.com/security/cve/CVE-2017-5483/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-5484 page", "url": "https://www.suse.com/security/cve/CVE-2017-5484/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-5485 page", "url": "https://www.suse.com/security/cve/CVE-2017-5485/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-5486 page", "url": "https://www.suse.com/security/cve/CVE-2017-5486/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-10103 page", "url": "https://www.suse.com/security/cve/CVE-2018-10103/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-10105 page", "url": "https://www.suse.com/security/cve/CVE-2018-10105/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14461 page", "url": "https://www.suse.com/security/cve/CVE-2018-14461/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14462 page", "url": "https://www.suse.com/security/cve/CVE-2018-14462/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14463 page", "url": "https://www.suse.com/security/cve/CVE-2018-14463/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14464 page", "url": "https://www.suse.com/security/cve/CVE-2018-14464/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14465 page", "url": "https://www.suse.com/security/cve/CVE-2018-14465/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14466 page", "url": "https://www.suse.com/security/cve/CVE-2018-14466/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14467 page", "url": "https://www.suse.com/security/cve/CVE-2018-14467/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14468 page", "url": "https://www.suse.com/security/cve/CVE-2018-14468/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14469 page", "url": "https://www.suse.com/security/cve/CVE-2018-14469/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14470 page", "url": "https://www.suse.com/security/cve/CVE-2018-14470/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14879 page", "url": "https://www.suse.com/security/cve/CVE-2018-14879/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14880 page", "url": "https://www.suse.com/security/cve/CVE-2018-14880/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14881 page", "url": "https://www.suse.com/security/cve/CVE-2018-14881/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-14882 page", "url": "https://www.suse.com/security/cve/CVE-2018-14882/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16227 page", "url": "https://www.suse.com/security/cve/CVE-2018-16227/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16228 page", "url": "https://www.suse.com/security/cve/CVE-2018-16228/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16229 page", "url": "https://www.suse.com/security/cve/CVE-2018-16229/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16230 page", "url": "https://www.suse.com/security/cve/CVE-2018-16230/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16300 page", "url": "https://www.suse.com/security/cve/CVE-2018-16300/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16301 page", "url": "https://www.suse.com/security/cve/CVE-2018-16301/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16451 page", "url": "https://www.suse.com/security/cve/CVE-2018-16451/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-16452 page", "url": "https://www.suse.com/security/cve/CVE-2018-16452/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-19519 page", "url": "https://www.suse.com/security/cve/CVE-2018-19519/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1010220 page", "url": "https://www.suse.com/security/cve/CVE-2019-1010220/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-15166 page", "url": "https://www.suse.com/security/cve/CVE-2019-15166/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-15167 page", "url": "https://www.suse.com/security/cve/CVE-2019-15167/" }, { "category": "self", "summary": "SUSE CVE CVE-2020-8037 page", "url": "https://www.suse.com/security/cve/CVE-2020-8037/" } ], "title": "tcpdump-4.99.1-1.2 on GA media", "tracking": { "current_release_date": "2024-06-15T00:00:00Z", "generator": { "date": "2024-06-15T00:00:00Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2024:11425-1", "initial_release_date": "2024-06-15T00:00:00Z", "revision_history": [ { "date": "2024-06-15T00:00:00Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "tcpdump-4.99.1-1.2.aarch64", "product": { "name": "tcpdump-4.99.1-1.2.aarch64", "product_id": "tcpdump-4.99.1-1.2.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "tcpdump-4.99.1-1.2.ppc64le", "product": { "name": "tcpdump-4.99.1-1.2.ppc64le", "product_id": "tcpdump-4.99.1-1.2.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "tcpdump-4.99.1-1.2.s390x", "product": { "name": "tcpdump-4.99.1-1.2.s390x", "product_id": "tcpdump-4.99.1-1.2.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "tcpdump-4.99.1-1.2.x86_64", "product": { "name": "tcpdump-4.99.1-1.2.x86_64", "product_id": "tcpdump-4.99.1-1.2.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "openSUSE Tumbleweed", "product": { "name": "openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed", "product_identification_helper": { "cpe": "cpe:/o:opensuse:tumbleweed" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.99.1-1.2.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64" }, "product_reference": "tcpdump-4.99.1-1.2.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.99.1-1.2.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le" }, "product_reference": "tcpdump-4.99.1-1.2.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.99.1-1.2.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x" }, "product_reference": "tcpdump-4.99.1-1.2.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.99.1-1.2.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" }, "product_reference": "tcpdump-4.99.1-1.2.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" } ] }, "vulnerabilities": [ { "cve": "CVE-2016-7922", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7922" } ], "notes": [ { "category": "general", "text": "The AH parser in tcpdump before 4.9.0 has a buffer overflow in print-ah.c:ah_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7922", "url": "https://www.suse.com/security/cve/CVE-2016-7922" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7922", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7922" }, { "cve": "CVE-2016-7923", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7923" } ], "notes": [ { "category": "general", "text": "The ARP parser in tcpdump before 4.9.0 has a buffer overflow in print-arp.c:arp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7923", "url": "https://www.suse.com/security/cve/CVE-2016-7923" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7923", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7923" }, { "cve": "CVE-2016-7924", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7924" } ], "notes": [ { "category": "general", "text": "The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:oam_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7924", "url": "https://www.suse.com/security/cve/CVE-2016-7924" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7924", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7924" }, { "cve": "CVE-2016-7925", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7925" } ], "notes": [ { "category": "general", "text": "The compressed SLIP parser in tcpdump before 4.9.0 has a buffer overflow in print-sl.c:sl_if_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7925", "url": "https://www.suse.com/security/cve/CVE-2016-7925" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7925", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7925" }, { "cve": "CVE-2016-7926", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7926" } ], "notes": [ { "category": "general", "text": "The Ethernet parser in tcpdump before 4.9.0 has a buffer overflow in print-ether.c:ethertype_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7926", "url": "https://www.suse.com/security/cve/CVE-2016-7926" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7926", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7926" }, { "cve": "CVE-2016-7927", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7927" } ], "notes": [ { "category": "general", "text": "The IEEE 802.11 parser in tcpdump before 4.9.0 has a buffer overflow in print-802_11.c:ieee802_11_radio_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7927", "url": "https://www.suse.com/security/cve/CVE-2016-7927" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7927", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7927" }, { "cve": "CVE-2016-7928", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7928" } ], "notes": [ { "category": "general", "text": "The IPComp parser in tcpdump before 4.9.0 has a buffer overflow in print-ipcomp.c:ipcomp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7928", "url": "https://www.suse.com/security/cve/CVE-2016-7928" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7928", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7928" }, { "cve": "CVE-2016-7929", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7929" } ], "notes": [ { "category": "general", "text": "The Juniper PPPoE ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-juniper.c:juniper_parse_header().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7929", "url": "https://www.suse.com/security/cve/CVE-2016-7929" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7929", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7929" }, { "cve": "CVE-2016-7930", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7930" } ], "notes": [ { "category": "general", "text": "The LLC/SNAP parser in tcpdump before 4.9.0 has a buffer overflow in print-llc.c:llc_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7930", "url": "https://www.suse.com/security/cve/CVE-2016-7930" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7930", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7930" }, { "cve": "CVE-2016-7931", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7931" } ], "notes": [ { "category": "general", "text": "The MPLS parser in tcpdump before 4.9.0 has a buffer overflow in print-mpls.c:mpls_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7931", "url": "https://www.suse.com/security/cve/CVE-2016-7931" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7931", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7931" }, { "cve": "CVE-2016-7932", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7932" } ], "notes": [ { "category": "general", "text": "The PIM parser in tcpdump before 4.9.0 has a buffer overflow in print-pim.c:pimv2_check_checksum().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7932", "url": "https://www.suse.com/security/cve/CVE-2016-7932" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7932", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7932" }, { "cve": "CVE-2016-7933", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7933" } ], "notes": [ { "category": "general", "text": "The PPP parser in tcpdump before 4.9.0 has a buffer overflow in print-ppp.c:ppp_hdlc_if_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7933", "url": "https://www.suse.com/security/cve/CVE-2016-7933" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7933", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7933" }, { "cve": "CVE-2016-7934", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7934" } ], "notes": [ { "category": "general", "text": "The RTCP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtcp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7934", "url": "https://www.suse.com/security/cve/CVE-2016-7934" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7934", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7934" }, { "cve": "CVE-2016-7935", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7935" } ], "notes": [ { "category": "general", "text": "The RTP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7935", "url": "https://www.suse.com/security/cve/CVE-2016-7935" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7935", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7935" }, { "cve": "CVE-2016-7936", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7936" } ], "notes": [ { "category": "general", "text": "The UDP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:udp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7936", "url": "https://www.suse.com/security/cve/CVE-2016-7936" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7936", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7936" }, { "cve": "CVE-2016-7937", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7937" } ], "notes": [ { "category": "general", "text": "The VAT parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:vat_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7937", "url": "https://www.suse.com/security/cve/CVE-2016-7937" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7937", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7937" }, { "cve": "CVE-2016-7938", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7938" } ], "notes": [ { "category": "general", "text": "The ZeroMQ parser in tcpdump before 4.9.0 has an integer overflow in print-zeromq.c:zmtp1_print_frame().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7938", "url": "https://www.suse.com/security/cve/CVE-2016-7938" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7938", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7938" }, { "cve": "CVE-2016-7939", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7939" } ], "notes": [ { "category": "general", "text": "The GRE parser in tcpdump before 4.9.0 has a buffer overflow in print-gre.c, multiple functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7939", "url": "https://www.suse.com/security/cve/CVE-2016-7939" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7939", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7939" }, { "cve": "CVE-2016-7940", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7940" } ], "notes": [ { "category": "general", "text": "The STP parser in tcpdump before 4.9.0 has a buffer overflow in print-stp.c, multiple functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7940", "url": "https://www.suse.com/security/cve/CVE-2016-7940" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7940", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7940" }, { "cve": "CVE-2016-7973", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7973" } ], "notes": [ { "category": "general", "text": "The AppleTalk parser in tcpdump before 4.9.0 has a buffer overflow in print-atalk.c, multiple functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7973", "url": "https://www.suse.com/security/cve/CVE-2016-7973" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7973", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7973" }, { "cve": "CVE-2016-7974", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7974" } ], "notes": [ { "category": "general", "text": "The IP parser in tcpdump before 4.9.0 has a buffer overflow in print-ip.c, multiple functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7974", "url": "https://www.suse.com/security/cve/CVE-2016-7974" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7974", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7974" }, { "cve": "CVE-2016-7975", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7975" } ], "notes": [ { "category": "general", "text": "The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7975", "url": "https://www.suse.com/security/cve/CVE-2016-7975" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7975", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7975" }, { "cve": "CVE-2016-7983", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7983" } ], "notes": [ { "category": "general", "text": "The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7983", "url": "https://www.suse.com/security/cve/CVE-2016-7983" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7983", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7983" }, { "cve": "CVE-2016-7984", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7984" } ], "notes": [ { "category": "general", "text": "The TFTP parser in tcpdump before 4.9.0 has a buffer overflow in print-tftp.c:tftp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7984", "url": "https://www.suse.com/security/cve/CVE-2016-7984" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7984", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7984" }, { "cve": "CVE-2016-7985", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7985" } ], "notes": [ { "category": "general", "text": "The CALM FAST parser in tcpdump before 4.9.0 has a buffer overflow in print-calm-fast.c:calm_fast_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7985", "url": "https://www.suse.com/security/cve/CVE-2016-7985" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7985", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7985" }, { "cve": "CVE-2016-7986", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7986" } ], "notes": [ { "category": "general", "text": "The GeoNetworking parser in tcpdump before 4.9.0 has a buffer overflow in print-geonet.c, multiple functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7986", "url": "https://www.suse.com/security/cve/CVE-2016-7986" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7986", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7986" }, { "cve": "CVE-2016-7992", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7992" } ], "notes": [ { "category": "general", "text": "The Classical IP over ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-cip.c:cip_if_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7992", "url": "https://www.suse.com/security/cve/CVE-2016-7992" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7992", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7992" }, { "cve": "CVE-2016-7993", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7993" } ], "notes": [ { "category": "general", "text": "A bug in util-print.c:relts_print() in tcpdump before 4.9.0 could cause a buffer overflow in multiple protocol parsers (DNS, DVMRP, HSRP, IGMP, lightweight resolver protocol, PIM).", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7993", "url": "https://www.suse.com/security/cve/CVE-2016-7993" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-7993", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-7993" }, { "cve": "CVE-2016-8574", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-8574" } ], "notes": [ { "category": "general", "text": "The FRF.15 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:frf15_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-8574", "url": "https://www.suse.com/security/cve/CVE-2016-8574" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-8574", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-8574" }, { "cve": "CVE-2016-8575", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-8575" } ], "notes": [ { "category": "general", "text": "The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2017-5482.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-8575", "url": "https://www.suse.com/security/cve/CVE-2016-8575" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2016-8575", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-8575" }, { "cve": "CVE-2017-11108", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-11108" } ], "notes": [ { "category": "general", "text": "tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-11108", "url": "https://www.suse.com/security/cve/CVE-2017-11108" }, { "category": "external", "summary": "SUSE Bug 1047873 for CVE-2017-11108", "url": "https://bugzilla.suse.com/1047873" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-11108", "url": "https://bugzilla.suse.com/1057247" }, { "category": "external", "summary": "SUSE Bug 1123142 for CVE-2017-11108", "url": "https://bugzilla.suse.com/1123142" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-11108" }, { "cve": "CVE-2017-11541", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-11541" } ], "notes": [ { "category": "general", "text": "tcpdump 4.9.0 has a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-11541", "url": "https://www.suse.com/security/cve/CVE-2017-11541" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-11541", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-11541", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-11541", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-11541", "url": "https://bugzilla.suse.com/1057247" }, { "category": "external", "summary": "SUSE Bug 1123142 for CVE-2017-11541", "url": "https://bugzilla.suse.com/1123142" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-11541" }, { "cve": "CVE-2017-11542", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-11542" } ], "notes": [ { "category": "general", "text": "tcpdump 4.9.0 has a heap-based buffer over-read in the pimv1_print function in print-pim.c.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-11542", "url": "https://www.suse.com/security/cve/CVE-2017-11542" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-11542", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-11542", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-11542", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-11542", "url": "https://bugzilla.suse.com/1057247" }, { "category": "external", "summary": "SUSE Bug 1123142 for CVE-2017-11542", "url": "https://bugzilla.suse.com/1123142" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-11542" }, { "cve": "CVE-2017-11543", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-11543" } ], "notes": [ { "category": "general", "text": "tcpdump 4.9.0 has a buffer overflow in the sliplink_print function in print-sl.c.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-11543", "url": "https://www.suse.com/security/cve/CVE-2017-11543" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-11543", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-11543", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-11543", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-11543", "url": "https://bugzilla.suse.com/1057247" }, { "category": "external", "summary": "SUSE Bug 1123142 for CVE-2017-11543", "url": "https://bugzilla.suse.com/1123142" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.3, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2017-11543" }, { "cve": "CVE-2017-12893", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12893" } ], "notes": [ { "category": "general", "text": "The SMB/CIFS parser in tcpdump before 4.9.2 has a buffer over-read in smbutil.c:name_len().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12893", "url": "https://www.suse.com/security/cve/CVE-2017-12893" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12893", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12893", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12893", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12893", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12893" }, { "cve": "CVE-2017-12894", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12894" } ], "notes": [ { "category": "general", "text": "Several protocol parsers in tcpdump before 4.9.2 could cause a buffer over-read in addrtoname.c:lookup_bytestring().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12894", "url": "https://www.suse.com/security/cve/CVE-2017-12894" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12894", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12894", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12894", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12894", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12894" }, { "cve": "CVE-2017-12895", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12895" } ], "notes": [ { "category": "general", "text": "The ICMP parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp.c:icmp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12895", "url": "https://www.suse.com/security/cve/CVE-2017-12895" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12895", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12895", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12895", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12895", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12895" }, { "cve": "CVE-2017-12896", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12896" } ], "notes": [ { "category": "general", "text": "The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12896", "url": "https://www.suse.com/security/cve/CVE-2017-12896" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12896", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12896", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12896", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12896", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12896" }, { "cve": "CVE-2017-12897", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12897" } ], "notes": [ { "category": "general", "text": "The ISO CLNS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isoclns_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12897", "url": "https://www.suse.com/security/cve/CVE-2017-12897" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12897", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12897", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12897", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12897", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12897" }, { "cve": "CVE-2017-12898", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12898" } ], "notes": [ { "category": "general", "text": "The NFS parser in tcpdump before 4.9.2 has a buffer over-read in print-nfs.c:interp_reply().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12898", "url": "https://www.suse.com/security/cve/CVE-2017-12898" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12898", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12898", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12898", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12898", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12898" }, { "cve": "CVE-2017-12899", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12899" } ], "notes": [ { "category": "general", "text": "The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12899", "url": "https://www.suse.com/security/cve/CVE-2017-12899" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12899", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12899", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12899", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12899", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12899" }, { "cve": "CVE-2017-12900", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12900" } ], "notes": [ { "category": "general", "text": "Several protocol parsers in tcpdump before 4.9.2 could cause a buffer over-read in util-print.c:tok2strbuf().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12900", "url": "https://www.suse.com/security/cve/CVE-2017-12900" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12900", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12900", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12900", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12900", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12900" }, { "cve": "CVE-2017-12901", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12901" } ], "notes": [ { "category": "general", "text": "The EIGRP parser in tcpdump before 4.9.2 has a buffer over-read in print-eigrp.c:eigrp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12901", "url": "https://www.suse.com/security/cve/CVE-2017-12901" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12901", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12901", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12901", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12901", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12901" }, { "cve": "CVE-2017-12902", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12902" } ], "notes": [ { "category": "general", "text": "The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12902", "url": "https://www.suse.com/security/cve/CVE-2017-12902" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12902", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12902", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12902", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12902", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12902" }, { "cve": "CVE-2017-12985", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12985" } ], "notes": [ { "category": "general", "text": "The IPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-ip6.c:ip6_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12985", "url": "https://www.suse.com/security/cve/CVE-2017-12985" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12985", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12985", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12985", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12985", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12985" }, { "cve": "CVE-2017-12986", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12986" } ], "notes": [ { "category": "general", "text": "The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12986", "url": "https://www.suse.com/security/cve/CVE-2017-12986" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12986", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12986", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12986", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12986", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12986" }, { "cve": "CVE-2017-12987", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12987" } ], "notes": [ { "category": "general", "text": "The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12987", "url": "https://www.suse.com/security/cve/CVE-2017-12987" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12987", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12987", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12987", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12987", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12987" }, { "cve": "CVE-2017-12988", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12988" } ], "notes": [ { "category": "general", "text": "The telnet parser in tcpdump before 4.9.2 has a buffer over-read in print-telnet.c:telnet_parse().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12988", "url": "https://www.suse.com/security/cve/CVE-2017-12988" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12988", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12988", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12988", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12988", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12988" }, { "cve": "CVE-2017-12989", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12989" } ], "notes": [ { "category": "general", "text": "The RESP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-resp.c:resp_get_length().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12989", "url": "https://www.suse.com/security/cve/CVE-2017-12989" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12989", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12989", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12989", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12989", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12989" }, { "cve": "CVE-2017-12990", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12990" } ], "notes": [ { "category": "general", "text": "The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12990", "url": "https://www.suse.com/security/cve/CVE-2017-12990" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12990", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12990", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12990", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12990", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12990" }, { "cve": "CVE-2017-12991", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12991" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12991", "url": "https://www.suse.com/security/cve/CVE-2017-12991" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12991", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12991", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12991", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12991", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12991" }, { "cve": "CVE-2017-12992", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12992" } ], "notes": [ { "category": "general", "text": "The RIPng parser in tcpdump before 4.9.2 has a buffer over-read in print-ripng.c:ripng_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12992", "url": "https://www.suse.com/security/cve/CVE-2017-12992" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12992", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12992", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12992", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12992", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12992" }, { "cve": "CVE-2017-12993", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12993" } ], "notes": [ { "category": "general", "text": "The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c, several functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12993", "url": "https://www.suse.com/security/cve/CVE-2017-12993" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12993", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12993", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12993", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12993", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12993" }, { "cve": "CVE-2017-12994", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12994" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12994", "url": "https://www.suse.com/security/cve/CVE-2017-12994" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12994", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12994", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12994", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12994", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12994" }, { "cve": "CVE-2017-12995", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12995" } ], "notes": [ { "category": "general", "text": "The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12995", "url": "https://www.suse.com/security/cve/CVE-2017-12995" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12995", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12995", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12995", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12995", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12995" }, { "cve": "CVE-2017-12996", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12996" } ], "notes": [ { "category": "general", "text": "The PIMv2 parser in tcpdump before 4.9.2 has a buffer over-read in print-pim.c:pimv2_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12996", "url": "https://www.suse.com/security/cve/CVE-2017-12996" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12996", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12996", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12996", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12996", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12996" }, { "cve": "CVE-2017-12997", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12997" } ], "notes": [ { "category": "general", "text": "The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12997", "url": "https://www.suse.com/security/cve/CVE-2017-12997" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12997", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12997", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12997", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12997", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12997" }, { "cve": "CVE-2017-12998", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12998" } ], "notes": [ { "category": "general", "text": "The IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print_extd_ip_reach().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12998", "url": "https://www.suse.com/security/cve/CVE-2017-12998" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12998", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12998", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12998", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12998", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12998" }, { "cve": "CVE-2017-12999", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-12999" } ], "notes": [ { "category": "general", "text": "The IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-12999", "url": "https://www.suse.com/security/cve/CVE-2017-12999" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-12999", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-12999", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-12999", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-12999", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-12999" }, { "cve": "CVE-2017-13000", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13000" } ], "notes": [ { "category": "general", "text": "The IEEE 802.15.4 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_15_4.c:ieee802_15_4_if_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13000", "url": "https://www.suse.com/security/cve/CVE-2017-13000" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13000", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13000", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13000", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13000", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13000" }, { "cve": "CVE-2017-13001", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13001" } ], "notes": [ { "category": "general", "text": "The NFS parser in tcpdump before 4.9.2 has a buffer over-read in print-nfs.c:nfs_printfh().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13001", "url": "https://www.suse.com/security/cve/CVE-2017-13001" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13001", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13001", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13001", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13001", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13001" }, { "cve": "CVE-2017-13002", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13002" } ], "notes": [ { "category": "general", "text": "The AODV parser in tcpdump before 4.9.2 has a buffer over-read in print-aodv.c:aodv_extension().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13002", "url": "https://www.suse.com/security/cve/CVE-2017-13002" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13002", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13002", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13002", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13002", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13002" }, { "cve": "CVE-2017-13003", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13003" } ], "notes": [ { "category": "general", "text": "The LMP parser in tcpdump before 4.9.2 has a buffer over-read in print-lmp.c:lmp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13003", "url": "https://www.suse.com/security/cve/CVE-2017-13003" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13003", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13003", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13003", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13003", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13003" }, { "cve": "CVE-2017-13004", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13004" } ], "notes": [ { "category": "general", "text": "The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c:juniper_parse_header().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13004", "url": "https://www.suse.com/security/cve/CVE-2017-13004" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13004", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13004", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13004", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13004", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13004" }, { "cve": "CVE-2017-13005", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13005" } ], "notes": [ { "category": "general", "text": "The NFS parser in tcpdump before 4.9.2 has a buffer over-read in print-nfs.c:xid_map_enter().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13005", "url": "https://www.suse.com/security/cve/CVE-2017-13005" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13005", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13005", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13005", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13005", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13005" }, { "cve": "CVE-2017-13006", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13006" } ], "notes": [ { "category": "general", "text": "The L2TP parser in tcpdump before 4.9.2 has a buffer over-read in print-l2tp.c, several functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13006", "url": "https://www.suse.com/security/cve/CVE-2017-13006" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13006", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13006", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13006", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13006", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13006" }, { "cve": "CVE-2017-13007", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13007" } ], "notes": [ { "category": "general", "text": "The Apple PKTAP parser in tcpdump before 4.9.2 has a buffer over-read in print-pktap.c:pktap_if_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13007", "url": "https://www.suse.com/security/cve/CVE-2017-13007" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13007", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13007", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13007", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13007", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13007" }, { "cve": "CVE-2017-13008", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13008" } ], "notes": [ { "category": "general", "text": "The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13008", "url": "https://www.suse.com/security/cve/CVE-2017-13008" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13008", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13008", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13008", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13008", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13008" }, { "cve": "CVE-2017-13009", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13009" } ], "notes": [ { "category": "general", "text": "The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13009", "url": "https://www.suse.com/security/cve/CVE-2017-13009" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13009", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13009", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13009", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13009", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13009" }, { "cve": "CVE-2017-13010", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13010" } ], "notes": [ { "category": "general", "text": "The BEEP parser in tcpdump before 4.9.2 has a buffer over-read in print-beep.c:l_strnstart().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13010", "url": "https://www.suse.com/security/cve/CVE-2017-13010" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13010", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13010", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13010", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13010", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13010" }, { "cve": "CVE-2017-13011", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13011" } ], "notes": [ { "category": "general", "text": "Several protocol parsers in tcpdump before 4.9.2 could cause a buffer overflow in util-print.c:bittok2str_internal().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13011", "url": "https://www.suse.com/security/cve/CVE-2017-13011" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13011", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13011", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13011", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13011", "url": "https://bugzilla.suse.com/1057247" }, { "category": "external", "summary": "SUSE Bug 1123142 for CVE-2017-13011", "url": "https://bugzilla.suse.com/1123142" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13011" }, { "cve": "CVE-2017-13012", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13012" } ], "notes": [ { "category": "general", "text": "The ICMP parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp.c:icmp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13012", "url": "https://www.suse.com/security/cve/CVE-2017-13012" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13012", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13012", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13012", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13012", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13012" }, { "cve": "CVE-2017-13013", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13013" } ], "notes": [ { "category": "general", "text": "The ARP parser in tcpdump before 4.9.2 has a buffer over-read in print-arp.c, several functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13013", "url": "https://www.suse.com/security/cve/CVE-2017-13013" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13013", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13013", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13013", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13013", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13013" }, { "cve": "CVE-2017-13014", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13014" } ], "notes": [ { "category": "general", "text": "The White Board protocol parser in tcpdump before 4.9.2 has a buffer over-read in print-wb.c:wb_prep(), several functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13014", "url": "https://www.suse.com/security/cve/CVE-2017-13014" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13014", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13014", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13014", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13014", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13014" }, { "cve": "CVE-2017-13015", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13015" } ], "notes": [ { "category": "general", "text": "The EAP parser in tcpdump before 4.9.2 has a buffer over-read in print-eap.c:eap_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13015", "url": "https://www.suse.com/security/cve/CVE-2017-13015" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13015", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13015", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13015", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13015", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13015" }, { "cve": "CVE-2017-13016", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13016" } ], "notes": [ { "category": "general", "text": "The ISO ES-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:esis_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13016", "url": "https://www.suse.com/security/cve/CVE-2017-13016" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13016", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13016", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13016", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13016", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13016" }, { "cve": "CVE-2017-13017", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13017" } ], "notes": [ { "category": "general", "text": "The DHCPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-dhcp6.c:dhcp6opt_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13017", "url": "https://www.suse.com/security/cve/CVE-2017-13017" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13017", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13017", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13017", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13017", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13017" }, { "cve": "CVE-2017-13018", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13018" } ], "notes": [ { "category": "general", "text": "The PGM parser in tcpdump before 4.9.2 has a buffer over-read in print-pgm.c:pgm_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13018", "url": "https://www.suse.com/security/cve/CVE-2017-13018" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13018", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13018", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13018", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13018", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13018" }, { "cve": "CVE-2017-13019", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13019" } ], "notes": [ { "category": "general", "text": "The PGM parser in tcpdump before 4.9.2 has a buffer over-read in print-pgm.c:pgm_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13019", "url": "https://www.suse.com/security/cve/CVE-2017-13019" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13019", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13019", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13019", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13019", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13019" }, { "cve": "CVE-2017-13020", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13020" } ], "notes": [ { "category": "general", "text": "The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13020", "url": "https://www.suse.com/security/cve/CVE-2017-13020" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13020", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13020", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13020", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13020", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13020" }, { "cve": "CVE-2017-13021", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13021" } ], "notes": [ { "category": "general", "text": "The ICMPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp6.c:icmp6_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13021", "url": "https://www.suse.com/security/cve/CVE-2017-13021" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13021", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13021", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13021", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13021", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13021" }, { "cve": "CVE-2017-13022", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13022" } ], "notes": [ { "category": "general", "text": "The IP parser in tcpdump before 4.9.2 has a buffer over-read in print-ip.c:ip_printroute().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13022", "url": "https://www.suse.com/security/cve/CVE-2017-13022" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13022", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13022", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13022", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13022", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13022" }, { "cve": "CVE-2017-13023", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13023" } ], "notes": [ { "category": "general", "text": "The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13023", "url": "https://www.suse.com/security/cve/CVE-2017-13023" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13023", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13023", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13023", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13023", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13023" }, { "cve": "CVE-2017-13024", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13024" } ], "notes": [ { "category": "general", "text": "The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13024", "url": "https://www.suse.com/security/cve/CVE-2017-13024" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13024", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13024", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13024", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13024", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13024" }, { "cve": "CVE-2017-13025", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13025" } ], "notes": [ { "category": "general", "text": "The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13025", "url": "https://www.suse.com/security/cve/CVE-2017-13025" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13025", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13025", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13025", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13025", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13025" }, { "cve": "CVE-2017-13026", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13026" } ], "notes": [ { "category": "general", "text": "The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c, several functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13026", "url": "https://www.suse.com/security/cve/CVE-2017-13026" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13026", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13026", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13026", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13026", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13026" }, { "cve": "CVE-2017-13027", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13027" } ], "notes": [ { "category": "general", "text": "The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_mgmt_addr_tlv_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13027", "url": "https://www.suse.com/security/cve/CVE-2017-13027" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13027", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13027", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13027", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13027", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13027" }, { "cve": "CVE-2017-13028", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13028" } ], "notes": [ { "category": "general", "text": "The BOOTP parser in tcpdump before 4.9.2 has a buffer over-read in print-bootp.c:bootp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13028", "url": "https://www.suse.com/security/cve/CVE-2017-13028" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13028", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13028", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13028", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13028", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13028" }, { "cve": "CVE-2017-13029", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13029" } ], "notes": [ { "category": "general", "text": "The PPP parser in tcpdump before 4.9.2 has a buffer over-read in print-ppp.c:print_ccp_config_options().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13029", "url": "https://www.suse.com/security/cve/CVE-2017-13029" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13029", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13029", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13029", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13029", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13029" }, { "cve": "CVE-2017-13030", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13030" } ], "notes": [ { "category": "general", "text": "The PIM parser in tcpdump before 4.9.2 has a buffer over-read in print-pim.c, several functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13030", "url": "https://www.suse.com/security/cve/CVE-2017-13030" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13030", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13030", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13030", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13030", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13030" }, { "cve": "CVE-2017-13031", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13031" } ], "notes": [ { "category": "general", "text": "The IPv6 fragmentation header parser in tcpdump before 4.9.2 has a buffer over-read in print-frag6.c:frag6_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13031", "url": "https://www.suse.com/security/cve/CVE-2017-13031" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13031", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13031", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13031", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13031", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13031" }, { "cve": "CVE-2017-13032", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13032" } ], "notes": [ { "category": "general", "text": "The RADIUS parser in tcpdump before 4.9.2 has a buffer over-read in print-radius.c:print_attr_string().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13032", "url": "https://www.suse.com/security/cve/CVE-2017-13032" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13032", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13032", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13032", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13032", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13032" }, { "cve": "CVE-2017-13033", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13033" } ], "notes": [ { "category": "general", "text": "The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13033", "url": "https://www.suse.com/security/cve/CVE-2017-13033" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13033", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13033", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13033", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13033", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13033" }, { "cve": "CVE-2017-13034", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13034" } ], "notes": [ { "category": "general", "text": "The PGM parser in tcpdump before 4.9.2 has a buffer over-read in print-pgm.c:pgm_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13034", "url": "https://www.suse.com/security/cve/CVE-2017-13034" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13034", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13034", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13034", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13034", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13034" }, { "cve": "CVE-2017-13035", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13035" } ], "notes": [ { "category": "general", "text": "The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print_id().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13035", "url": "https://www.suse.com/security/cve/CVE-2017-13035" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13035", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13035", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13035", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13035", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13035" }, { "cve": "CVE-2017-13036", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13036" } ], "notes": [ { "category": "general", "text": "The OSPFv3 parser in tcpdump before 4.9.2 has a buffer over-read in print-ospf6.c:ospf6_decode_v3().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13036", "url": "https://www.suse.com/security/cve/CVE-2017-13036" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13036", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13036", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13036", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13036", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13036" }, { "cve": "CVE-2017-13037", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13037" } ], "notes": [ { "category": "general", "text": "The IP parser in tcpdump before 4.9.2 has a buffer over-read in print-ip.c:ip_printts().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13037", "url": "https://www.suse.com/security/cve/CVE-2017-13037" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13037", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13037", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13037", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13037", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13037" }, { "cve": "CVE-2017-13038", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13038" } ], "notes": [ { "category": "general", "text": "The PPP parser in tcpdump before 4.9.2 has a buffer over-read in print-ppp.c:handle_mlppp().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13038", "url": "https://www.suse.com/security/cve/CVE-2017-13038" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13038", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13038", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13038", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13038", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13038" }, { "cve": "CVE-2017-13039", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13039" } ], "notes": [ { "category": "general", "text": "The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c, several functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13039", "url": "https://www.suse.com/security/cve/CVE-2017-13039" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13039", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13039", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13039", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13039", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13039" }, { "cve": "CVE-2017-13040", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13040" } ], "notes": [ { "category": "general", "text": "The MPTCP parser in tcpdump before 4.9.2 has a buffer over-read in print-mptcp.c, several functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13040", "url": "https://www.suse.com/security/cve/CVE-2017-13040" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13040", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13040", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13040", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13040", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13040" }, { "cve": "CVE-2017-13041", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13041" } ], "notes": [ { "category": "general", "text": "The ICMPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp6.c:icmp6_nodeinfo_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13041", "url": "https://www.suse.com/security/cve/CVE-2017-13041" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13041", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13041", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13041", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13041", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13041" }, { "cve": "CVE-2017-13042", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13042" } ], "notes": [ { "category": "general", "text": "The HNCP parser in tcpdump before 4.9.2 has a buffer over-read in print-hncp.c:dhcpv6_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13042", "url": "https://www.suse.com/security/cve/CVE-2017-13042" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13042", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13042", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13042", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13042", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13042" }, { "cve": "CVE-2017-13043", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13043" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:decode_multicast_vpn().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13043", "url": "https://www.suse.com/security/cve/CVE-2017-13043" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13043", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13043", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13043", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13043", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13043" }, { "cve": "CVE-2017-13044", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13044" } ], "notes": [ { "category": "general", "text": "The HNCP parser in tcpdump before 4.9.2 has a buffer over-read in print-hncp.c:dhcpv4_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13044", "url": "https://www.suse.com/security/cve/CVE-2017-13044" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13044", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13044", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13044", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13044", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13044" }, { "cve": "CVE-2017-13045", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13045" } ], "notes": [ { "category": "general", "text": "The VQP parser in tcpdump before 4.9.2 has a buffer over-read in print-vqp.c:vqp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13045", "url": "https://www.suse.com/security/cve/CVE-2017-13045" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13045", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13045", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13045", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13045", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13045" }, { "cve": "CVE-2017-13046", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13046" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13046", "url": "https://www.suse.com/security/cve/CVE-2017-13046" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13046", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13046", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13046", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13046", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13046" }, { "cve": "CVE-2017-13047", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13047" } ], "notes": [ { "category": "general", "text": "The ISO ES-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:esis_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13047", "url": "https://www.suse.com/security/cve/CVE-2017-13047" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13047", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13047", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13047", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13047", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13047" }, { "cve": "CVE-2017-13048", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13048" } ], "notes": [ { "category": "general", "text": "The RSVP parser in tcpdump before 4.9.2 has a buffer over-read in print-rsvp.c:rsvp_obj_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13048", "url": "https://www.suse.com/security/cve/CVE-2017-13048" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13048", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13048", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13048", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13048", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13048" }, { "cve": "CVE-2017-13049", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13049" } ], "notes": [ { "category": "general", "text": "The Rx protocol parser in tcpdump before 4.9.2 has a buffer over-read in print-rx.c:ubik_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13049", "url": "https://www.suse.com/security/cve/CVE-2017-13049" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13049", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13049", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13049", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13049", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13049" }, { "cve": "CVE-2017-13050", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13050" } ], "notes": [ { "category": "general", "text": "The RPKI-Router parser in tcpdump before 4.9.2 has a buffer over-read in print-rpki-rtr.c:rpki_rtr_pdu_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13050", "url": "https://www.suse.com/security/cve/CVE-2017-13050" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13050", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13050", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13050", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13050", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13050" }, { "cve": "CVE-2017-13051", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13051" } ], "notes": [ { "category": "general", "text": "The RSVP parser in tcpdump before 4.9.2 has a buffer over-read in print-rsvp.c:rsvp_obj_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13051", "url": "https://www.suse.com/security/cve/CVE-2017-13051" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13051", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13051", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13051", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13051", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13051" }, { "cve": "CVE-2017-13052", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13052" } ], "notes": [ { "category": "general", "text": "The CFM parser in tcpdump before 4.9.2 has a buffer over-read in print-cfm.c:cfm_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13052", "url": "https://www.suse.com/security/cve/CVE-2017-13052" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13052", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13052", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13052", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13052", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13052" }, { "cve": "CVE-2017-13053", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13053" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:decode_rt_routing_info().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13053", "url": "https://www.suse.com/security/cve/CVE-2017-13053" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13053", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13053", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13053", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13053", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13053" }, { "cve": "CVE-2017-13054", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13054" } ], "notes": [ { "category": "general", "text": "The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_private_8023_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13054", "url": "https://www.suse.com/security/cve/CVE-2017-13054" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13054", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13054", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13054", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13054", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13054" }, { "cve": "CVE-2017-13055", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13055" } ], "notes": [ { "category": "general", "text": "The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print_is_reach_subtlv().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13055", "url": "https://www.suse.com/security/cve/CVE-2017-13055" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13055", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13055", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13055", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13055", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13055" }, { "cve": "CVE-2017-13687", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13687" } ], "notes": [ { "category": "general", "text": "The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13687", "url": "https://www.suse.com/security/cve/CVE-2017-13687" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13687", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13687", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13687", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13687", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13687" }, { "cve": "CVE-2017-13688", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13688" } ], "notes": [ { "category": "general", "text": "The OLSR parser in tcpdump before 4.9.2 has a buffer over-read in print-olsr.c:olsr_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13688", "url": "https://www.suse.com/security/cve/CVE-2017-13688" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13688", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13688", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13688", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13688", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13688" }, { "cve": "CVE-2017-13689", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13689" } ], "notes": [ { "category": "general", "text": "The IKEv1 parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:ikev1_id_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13689", "url": "https://www.suse.com/security/cve/CVE-2017-13689" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13689", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13689", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13689", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13689", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13689" }, { "cve": "CVE-2017-13690", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13690" } ], "notes": [ { "category": "general", "text": "The IKEv2 parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c, several functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13690", "url": "https://www.suse.com/security/cve/CVE-2017-13690" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13690", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13690", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13690", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13690", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13690" }, { "cve": "CVE-2017-13725", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-13725" } ], "notes": [ { "category": "general", "text": "The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-13725", "url": "https://www.suse.com/security/cve/CVE-2017-13725" }, { "category": "external", "summary": "SUSE Bug 1050219 for CVE-2017-13725", "url": "https://bugzilla.suse.com/1050219" }, { "category": "external", "summary": "SUSE Bug 1050222 for CVE-2017-13725", "url": "https://bugzilla.suse.com/1050222" }, { "category": "external", "summary": "SUSE Bug 1050225 for CVE-2017-13725", "url": "https://bugzilla.suse.com/1050225" }, { "category": "external", "summary": "SUSE Bug 1057247 for CVE-2017-13725", "url": "https://bugzilla.suse.com/1057247" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2017-13725" }, { "cve": "CVE-2017-16808", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-16808" } ], "notes": [ { "category": "general", "text": "tcpdump before 4.9.3 has a heap-based buffer over-read related to aoe_print in print-aoe.c and lookup_emem in addrtoname.c.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-16808", "url": "https://www.suse.com/security/cve/CVE-2017-16808" }, { "category": "external", "summary": "SUSE Bug 1068716 for CVE-2017-16808", "url": "https://bugzilla.suse.com/1068716" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2017-16808", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2017-16808" }, { "cve": "CVE-2017-5202", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-5202" } ], "notes": [ { "category": "general", "text": "The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-5202", "url": "https://www.suse.com/security/cve/CVE-2017-5202" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2017-5202", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-5202" }, { "cve": "CVE-2017-5203", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-5203" } ], "notes": [ { "category": "general", "text": "The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-5203", "url": "https://www.suse.com/security/cve/CVE-2017-5203" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2017-5203", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-5203" }, { "cve": "CVE-2017-5204", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-5204" } ], "notes": [ { "category": "general", "text": "The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-5204", "url": "https://www.suse.com/security/cve/CVE-2017-5204" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2017-5204", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-5204" }, { "cve": "CVE-2017-5205", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-5205" } ], "notes": [ { "category": "general", "text": "The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-5205", "url": "https://www.suse.com/security/cve/CVE-2017-5205" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2017-5205", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-5205" }, { "cve": "CVE-2017-5341", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-5341" } ], "notes": [ { "category": "general", "text": "The OTV parser in tcpdump before 4.9.0 has a buffer overflow in print-otv.c:otv_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-5341", "url": "https://www.suse.com/security/cve/CVE-2017-5341" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2017-5341", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-5341" }, { "cve": "CVE-2017-5342", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-5342" } ], "notes": [ { "category": "general", "text": "In tcpdump before 4.9.0, a bug in multiple protocol parsers (Geneve, GRE, NSH, OTV, VXLAN and VXLAN GPE) could cause a buffer overflow in print-ether.c:ether_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-5342", "url": "https://www.suse.com/security/cve/CVE-2017-5342" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2017-5342", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-5342" }, { "cve": "CVE-2017-5482", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-5482" } ], "notes": [ { "category": "general", "text": "The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-5482", "url": "https://www.suse.com/security/cve/CVE-2017-5482" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2017-5482", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-5482" }, { "cve": "CVE-2017-5483", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-5483" } ], "notes": [ { "category": "general", "text": "The SNMP parser in tcpdump before 4.9.0 has a buffer overflow in print-snmp.c:asn1_parse().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-5483", "url": "https://www.suse.com/security/cve/CVE-2017-5483" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2017-5483", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-5483" }, { "cve": "CVE-2017-5484", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-5484" } ], "notes": [ { "category": "general", "text": "The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-5484", "url": "https://www.suse.com/security/cve/CVE-2017-5484" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2017-5484", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-5484" }, { "cve": "CVE-2017-5485", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-5485" } ], "notes": [ { "category": "general", "text": "The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in addrtoname.c:lookup_nsap().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-5485", "url": "https://www.suse.com/security/cve/CVE-2017-5485" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2017-5485", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-5485" }, { "cve": "CVE-2017-5486", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-5486" } ], "notes": [ { "category": "general", "text": "The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-5486", "url": "https://www.suse.com/security/cve/CVE-2017-5486" }, { "category": "external", "summary": "SUSE Bug 1020940 for CVE-2017-5486", "url": "https://bugzilla.suse.com/1020940" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-5486" }, { "cve": "CVE-2018-10103", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-10103" } ], "notes": [ { "category": "general", "text": "tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2).", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-10103", "url": "https://www.suse.com/security/cve/CVE-2018-10103" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-10103", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-10103" }, { "cve": "CVE-2018-10105", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-10105" } ], "notes": [ { "category": "general", "text": "tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2).", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-10105", "url": "https://www.suse.com/security/cve/CVE-2018-10105" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-10105", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-10105" }, { "cve": "CVE-2018-14461", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14461" } ], "notes": [ { "category": "general", "text": "The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14461", "url": "https://www.suse.com/security/cve/CVE-2018-14461" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14461", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14461" }, { "cve": "CVE-2018-14462", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14462" } ], "notes": [ { "category": "general", "text": "The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14462", "url": "https://www.suse.com/security/cve/CVE-2018-14462" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14462", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14462" }, { "cve": "CVE-2018-14463", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14463" } ], "notes": [ { "category": "general", "text": "The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14463", "url": "https://www.suse.com/security/cve/CVE-2018-14463" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14463", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14463" }, { "cve": "CVE-2018-14464", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14464" } ], "notes": [ { "category": "general", "text": "The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14464", "url": "https://www.suse.com/security/cve/CVE-2018-14464" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14464", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14464" }, { "cve": "CVE-2018-14465", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14465" } ], "notes": [ { "category": "general", "text": "The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14465", "url": "https://www.suse.com/security/cve/CVE-2018-14465" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14465", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14465" }, { "cve": "CVE-2018-14466", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14466" } ], "notes": [ { "category": "general", "text": "The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14466", "url": "https://www.suse.com/security/cve/CVE-2018-14466" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14466", "url": "https://bugzilla.suse.com/1153098" }, { "category": "external", "summary": "SUSE Bug 1166972 for CVE-2018-14466", "url": "https://bugzilla.suse.com/1166972" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14466" }, { "cve": "CVE-2018-14467", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14467" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14467", "url": "https://www.suse.com/security/cve/CVE-2018-14467" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14467", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14467" }, { "cve": "CVE-2018-14468", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14468" } ], "notes": [ { "category": "general", "text": "The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14468", "url": "https://www.suse.com/security/cve/CVE-2018-14468" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14468", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14468" }, { "cve": "CVE-2018-14469", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14469" } ], "notes": [ { "category": "general", "text": "The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14469", "url": "https://www.suse.com/security/cve/CVE-2018-14469" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14469", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14469" }, { "cve": "CVE-2018-14470", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14470" } ], "notes": [ { "category": "general", "text": "The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14470", "url": "https://www.suse.com/security/cve/CVE-2018-14470" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14470", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14470" }, { "cve": "CVE-2018-14879", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14879" } ], "notes": [ { "category": "general", "text": "The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14879", "url": "https://www.suse.com/security/cve/CVE-2018-14879" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14879", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 0, "baseSeverity": "NONE", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "low" } ], "title": "CVE-2018-14879" }, { "cve": "CVE-2018-14880", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14880" } ], "notes": [ { "category": "general", "text": "The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14880", "url": "https://www.suse.com/security/cve/CVE-2018-14880" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14880", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14880" }, { "cve": "CVE-2018-14881", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14881" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14881", "url": "https://www.suse.com/security/cve/CVE-2018-14881" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14881", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14881" }, { "cve": "CVE-2018-14882", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-14882" } ], "notes": [ { "category": "general", "text": "The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-14882", "url": "https://www.suse.com/security/cve/CVE-2018-14882" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-14882", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-14882" }, { "cve": "CVE-2018-16227", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16227" } ], "notes": [ { "category": "general", "text": "The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16227", "url": "https://www.suse.com/security/cve/CVE-2018-16227" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16227", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-16227" }, { "cve": "CVE-2018-16228", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16228" } ], "notes": [ { "category": "general", "text": "The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16228", "url": "https://www.suse.com/security/cve/CVE-2018-16228" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16228", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-16228" }, { "cve": "CVE-2018-16229", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16229" } ], "notes": [ { "category": "general", "text": "The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option().", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16229", "url": "https://www.suse.com/security/cve/CVE-2018-16229" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16229", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-16229" }, { "cve": "CVE-2018-16230", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16230" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16230", "url": "https://www.suse.com/security/cve/CVE-2018-16230" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16230", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-16230" }, { "cve": "CVE-2018-16300", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16300" } ], "notes": [ { "category": "general", "text": "The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16300", "url": "https://www.suse.com/security/cve/CVE-2018-16300" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16300", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2018-16300" }, { "cve": "CVE-2018-16301", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16301" } ], "notes": [ { "category": "general", "text": "The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacker needs to create a 4GB file on the local filesystem and to specify the file name as the value of the -F command-line argument of tcpdump.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16301", "url": "https://www.suse.com/security/cve/CVE-2018-16301" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16301", "url": "https://bugzilla.suse.com/1153098" }, { "category": "external", "summary": "SUSE Bug 1153332 for CVE-2018-16301", "url": "https://bugzilla.suse.com/1153332" }, { "category": "external", "summary": "SUSE Bug 1195825 for CVE-2018-16301", "url": "https://bugzilla.suse.com/1195825" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2018-16301" }, { "cve": "CVE-2018-16451", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16451" } ], "notes": [ { "category": "general", "text": "The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \\MAILSLOT\\BROWSE and \\PIPE\\LANMAN.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16451", "url": "https://www.suse.com/security/cve/CVE-2018-16451" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16451", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-16451" }, { "cve": "CVE-2018-16452", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-16452" } ], "notes": [ { "category": "general", "text": "The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-16452", "url": "https://www.suse.com/security/cve/CVE-2018-16452" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2018-16452", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-16452" }, { "cve": "CVE-2018-19519", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-19519" } ], "notes": [ { "category": "general", "text": "In tcpdump 4.9.2, a stack-based buffer over-read exists in the print_prefix function of print-hncp.c via crafted packet data because of missing initialization.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-19519", "url": "https://www.suse.com/security/cve/CVE-2018-19519" }, { "category": "external", "summary": "SUSE Bug 1117267 for CVE-2018-19519", "url": "https://bugzilla.suse.com/1117267" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-19519" }, { "cve": "CVE-2019-1010220", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1010220" } ], "notes": [ { "category": "general", "text": "tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: \"ND_PRINT((ndo, \"%s\", buf));\", in function named \"print_prefix\", in \"print-hncp.c\". The attack vector is: The victim must open a specially crafted pcap file.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1010220", "url": "https://www.suse.com/security/cve/CVE-2019-1010220" }, { "category": "external", "summary": "SUSE Bug 1142439 for CVE-2019-1010220", "url": "https://bugzilla.suse.com/1142439" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2019-1010220", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2019-1010220" }, { "cve": "CVE-2019-15166", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-15166" } ], "notes": [ { "category": "general", "text": "lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-15166", "url": "https://www.suse.com/security/cve/CVE-2019-15166" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2019-15166", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2019-15166" }, { "cve": "CVE-2019-15167", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-15167" } ], "notes": [ { "category": "general", "text": "The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-15167", "url": "https://www.suse.com/security/cve/CVE-2019-15167" }, { "category": "external", "summary": "SUSE Bug 1153098 for CVE-2019-15167", "url": "https://bugzilla.suse.com/1153098" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2019-15167" }, { "cve": "CVE-2020-8037", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-8037" } ], "notes": [ { "category": "general", "text": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-8037", "url": "https://www.suse.com/security/cve/CVE-2020-8037" }, { "category": "external", "summary": "SUSE Bug 1178466 for CVE-2020-8037", "url": "https://bugzilla.suse.com/1178466" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.aarch64", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.ppc64le", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.s390x", "openSUSE Tumbleweed:tcpdump-4.99.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2020-8037" } ] }
opensuse-su-2020:1986-1
Vulnerability from csaf_opensuse
Published
2020-11-21 05:23
Modified
2020-11-21 05:23
Summary
Security update for tcpdump
Notes
Title of the patch
Security update for tcpdump
Description of the patch
This update for tcpdump fixes the following issues:
- CVE-2020-8037: Fixed an issue where PPP decapsulator did not allocate the right buffer size (bsc#1178466).
This update was imported from the SUSE:SLE-15:Update update project.
Patchnames
openSUSE-2020-1986
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for tcpdump", "title": "Title of the patch" }, { "category": "description", "text": "This update for tcpdump fixes the following issues:\n\n- CVE-2020-8037: Fixed an issue where PPP decapsulator did not allocate the right buffer size (bsc#1178466).\n\nThis update was imported from the SUSE:SLE-15:Update update project.", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-2020-1986", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2020_1986-1.json" }, { "category": "self", "summary": "URL for openSUSE-SU-2020:1986-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QLS7QAB5MKRGXWLJ5MLIV2TPU4TWVXE5/" }, { "category": "self", "summary": "E-Mail link for openSUSE-SU-2020:1986-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QLS7QAB5MKRGXWLJ5MLIV2TPU4TWVXE5/" }, { "category": "self", "summary": "SUSE Bug 1178466", "url": "https://bugzilla.suse.com/1178466" }, { "category": "self", "summary": "SUSE CVE CVE-2020-8037 page", "url": "https://www.suse.com/security/cve/CVE-2020-8037/" } ], "title": "Security update for tcpdump", "tracking": { "current_release_date": "2020-11-21T05:23:29Z", "generator": { "date": "2020-11-21T05:23:29Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2020:1986-1", "initial_release_date": "2020-11-21T05:23:29Z", "revision_history": [ { "date": "2020-11-21T05:23:29Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "tcpdump-4.9.2-lp152.7.3.1.x86_64", "product": { "name": "tcpdump-4.9.2-lp152.7.3.1.x86_64", "product_id": "tcpdump-4.9.2-lp152.7.3.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "openSUSE Leap 15.2", "product": { "name": "openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2", "product_identification_helper": { "cpe": "cpe:/o:opensuse:leap:15.2" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "tcpdump-4.9.2-lp152.7.3.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:tcpdump-4.9.2-lp152.7.3.1.x86_64" }, "product_reference": "tcpdump-4.9.2-lp152.7.3.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" } ] }, "vulnerabilities": [ { "cve": "CVE-2020-8037", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-8037" } ], "notes": [ { "category": "general", "text": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Leap 15.2:tcpdump-4.9.2-lp152.7.3.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-8037", "url": "https://www.suse.com/security/cve/CVE-2020-8037" }, { "category": "external", "summary": "SUSE Bug 1178466 for CVE-2020-8037", "url": "https://bugzilla.suse.com/1178466" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Leap 15.2:tcpdump-4.9.2-lp152.7.3.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "openSUSE Leap 15.2:tcpdump-4.9.2-lp152.7.3.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2020-11-21T05:23:29Z", "details": "moderate" } ], "title": "CVE-2020-8037" } ] }
wid-sec-w-2022-0571
Vulnerability from csaf_certbund
Published
2021-11-09 23:00
Modified
2025-01-15 23:00
Summary
Red Hat Enterprise Linux: Mehrere Schwachstellen
Notes
Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen.
Produktbeschreibung
Red Hat Enterprise Linux (RHEL) ist eine populäre Linux-Distribution.
Angriff
Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuführen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuführen.
Betroffene Betriebssysteme
- Linux
- UNIX
{ "document": { "aggregate_severity": { "text": "hoch" }, "category": "csaf_base", "csaf_version": "2.0", "distribution": { "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "de-DE", "notes": [ { "category": "legal_disclaimer", "text": "Das BSI ist als Anbieter f\u00fcr die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch daf\u00fcr verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgf\u00e4ltig im Einzelfall zu pr\u00fcfen." }, { "category": "description", "text": "Red Hat Enterprise Linux (RHEL) ist eine popul\u00e4re Linux-Distribution.", "title": "Produktbeschreibung" }, { "category": "summary", "text": "Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren.", "title": "Angriff" }, { "category": "general", "text": "- Linux\n- UNIX", "title": "Betroffene Betriebssysteme" } ], "publisher": { "category": "other", "contact_details": "csaf-provider@cert-bund.de", "name": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik", "namespace": "https://www.bsi.bund.de" }, "references": [ { "category": "self", "summary": "WID-SEC-W-2022-0571 - CSAF Version", "url": "https://wid.cert-bund.de/.well-known/csaf/white/2021/wid-sec-w-2022-0571.json" }, { "category": "self", "summary": "WID-SEC-2022-0571 - Portal Version", "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-0571" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4158" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4172" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4201" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4221" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4222" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4236" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4270" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4288" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4316" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4321" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4374" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4382" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4408" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4413" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4426" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4455" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4464" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4510" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4513" }, { "category": "external", "summary": "Red Hat Security Advisory vom 2021-11-09", "url": "https://access.redhat.com/errata/RHSA-2021:4519" }, { "category": "external", "summary": "AVAYA Security Advisory ASA-2021-159 vom 2021-11-11", "url": "https://downloads.avaya.com/css/P8/documents/101078544" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2021:4032 vom 2021-11-17", "url": "https://access.redhat.com/errata/RHSA-2021:4032" }, { "category": "external", "summary": "Oracle Linux Security Advisory ELSA-2021-4382 vom 2021-11-16", "url": "https://linux.oracle.com/errata/ELSA-2021-4382.html" }, { "category": "external", "summary": "Oracle Linux Security Advisory ELSA-2021-4222 vom 2021-11-17", "url": "https://linux.oracle.com/errata/ELSA-2021-4222.html" }, { "category": "external", "summary": "Oracle Linux Security Advisory ELSA-2021-4221 vom 2021-11-17", "url": "https://linux.oracle.com/errata/ELSA-2021-4221.html" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2021:4848 vom 2021-11-29", "url": "https://access.redhat.com/errata/RHSA-2021:4848" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2021:4845 vom 2021-11-29", "url": "https://access.redhat.com/errata/RHSA-2021:4845" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2021:3945-1 vom 2021-12-06", "url": "https://lists.suse.com/pipermail/sle-security-updates/2021-December/009858.html" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2021:4002-1 vom 2021-12-13", "url": "https://lists.suse.com/pipermail/sle-security-updates/2021-December/009887.html" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2021:4001-1 vom 2021-12-13", "url": "https://lists.suse.com/pipermail/sle-security-updates/2021-December/009888.html" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2021:4051-1 vom 2021-12-14", "url": "https://lists.suse.com/pipermail/sle-security-updates/2021-December/009896.html" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2021:4155-1 vom 2021-12-22", "url": "https://lists.suse.com/pipermail/sle-security-updates/2021-December/009927.html" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2022:0064-1 vom 2022-01-12", "url": "https://lists.suse.com/pipermail/sle-security-updates/2022-January/010000.html" }, { "category": "external", "summary": "Ubuntu Security Notice USN-5241-1 vom 2022-01-19", "url": "https://ubuntu.com/security/notices/USN-5241-1" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2022:0184-1 vom 2022-01-25", "url": "https://lists.suse.com/pipermail/sle-security-updates/2022-January/010072.html" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2022:0318 vom 2022-01-27", "url": "https://access.redhat.com/errata/RHSA-2022:0318" }, { "category": "external", "summary": "Amazon Linux Security Advisory ALAS-2022-1742 vom 2022-01-27", "url": "https://alas.aws.amazon.com/AL2/ALAS-2022-1742.html" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2022:0434 vom 2022-02-04", "url": "https://access.redhat.com/errata/RHSA-2022:0434" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2022:0184-2 vom 2022-02-17", "url": "https://lists.suse.com/pipermail/sle-security-updates/2022-February/010235.html" }, { "category": "external", "summary": "Amazon Linux Security Advisory ALAS-2022-030 vom 2022-02-26", "url": "https://alas.aws.amazon.com/AL2022/ALAS-2022-030.html" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2022:23018-1 vom 2022-03-04", "url": "https://lists.suse.com/pipermail/sle-security-updates/2022-March/010347.html" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2022:0856 vom 2022-03-14", "url": "https://access.redhat.com/errata/RHSA-2022:0856" }, { "category": "external", "summary": "Ubuntu Security Notice USN-5391-1 vom 2022-04-27", "url": "https://ubuntu.com/security/notices/USN-5391-1" }, { "category": "external", "summary": "Oracle Linux Security Advisory ELSA-2022-9341 vom 2022-04-28", "url": "https://linux.oracle.com/errata/ELSA-2022-9341.html" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2022:5498 vom 2022-07-05", "url": "https://access.redhat.com/errata/RHSA-2022:5498" }, { "category": "external", "summary": "Amazon Linux Security Advisory ALAS-2022-093 vom 2022-07-21", "url": "https://alas.aws.amazon.com/AL2022/ALAS-2022-093.html" }, { "category": "external", "summary": "Ubuntu Security Notice USN-5553-1 vom 2022-08-08", "url": "https://ubuntu.com/security/notices/USN-5553-1" }, { "category": "external", "summary": "Gentoo Linux Security Advisory GLSA-202208-03 vom 2022-08-09", "url": "https://security.gentoo.org/glsa/202208-03" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2022:3001-1 vom 2022-09-02", "url": "https://lists.suse.com/pipermail/sle-security-updates/2022-September/012070.html" }, { "category": "external", "summary": "Ubuntu Security Notice USN-5631-1 vom 2022-09-22", "url": "https://ubuntu.com/security/notices/USN-5631-1" }, { "category": "external", "summary": "Gentoo Linux Security Advisory GLSA-202210-09 vom 2022-10-16", "url": "https://security.gentoo.org/glsa/202210-09" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2022:3590-1 vom 2022-10-14", "url": "https://lists.suse.com/pipermail/sle-security-updates/2022-October/012537.html" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2022:3836-1 vom 2022-11-01", "url": "https://lists.suse.com/pipermail/sle-security-updates/2022-November/012792.html" }, { "category": "external", "summary": "Oracle Linux Security Advisory ELSA-2022-7529 vom 2022-11-15", "url": "https://linux.oracle.com/errata/ELSA-2022-7529.html" }, { "category": "external", "summary": "Amazon Linux Security Advisory ALAS-2023-2010 vom 2023-04-05", "url": "https://alas.aws.amazon.com/AL2/ALAS-2023-2010.html" }, { "category": "external", "summary": "Oracle Linux Security Advisory ELSA-2023-12349 vom 2023-05-24", "url": "http://linux.oracle.com/errata/ELSA-2023-12349.html" }, { "category": "external", "summary": "Amazon Linux Security Advisory ALAS2-2023-2079 vom 2023-06-08", "url": "https://alas.aws.amazon.com/AL2/ALAS-2023-2079.html" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2023:4053 vom 2023-07-19", "url": "https://access.redhat.com/errata/RHSA-2023:4053" }, { "category": "external", "summary": "Amazon Linux Security Advisory ALASSELINUX-NG-2023-001 vom 2023-09-27", "url": "https://alas.aws.amazon.com/AL2/ALASSELINUX-NG-2023-001.html" }, { "category": "external", "summary": "Amazon Linux Security Advisory ALAS2-2023-2307 vom 2023-10-20", "url": "https://alas.aws.amazon.com/AL2/ALAS-2023-2307.html" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2023:6431 vom 2023-11-07", "url": "https://access.redhat.com/errata/RHSA-2023:6431" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2023:6976 vom 2023-11-15", "url": "https://access.redhat.com/errata/RHSA-2023:6976" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2023:7820 vom 2023-12-14", "url": "https://access.redhat.com/errata/RHSA-2023:7820" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2024:0411 vom 2024-01-25", "url": "https://access.redhat.com/errata/RHSA-2024:0411" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2024:0573 vom 2024-01-30", "url": "https://access.redhat.com/errata/RHSA-2024:0573" }, { "category": "external", "summary": "Amazon Linux Security Advisory ALAS-2024-1918 vom 2024-02-06", "url": "https://alas.aws.amazon.com/ALAS-2024-1918.html" }, { "category": "external", "summary": "Amazon Linux Security Advisory ALAS-2024-1921 vom 2024-02-19", "url": "https://alas.aws.amazon.com/ALAS-2024-1921.html" }, { "category": "external", "summary": "Amazon Linux Security Advisory ALAS-2024-1921 vom 2024-02-19", "url": "https://www.cybersecurity-help.cz/vdb/SB2024021950" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2024:1086 vom 2024-03-05", "url": "https://access.redhat.com/errata/RHSA-2024:1086" }, { "category": "external", "summary": "Red Hat Security Advisory RHSA-2024:1154 vom 2024-03-06", "url": "https://access.redhat.com/errata/RHSA-2024:1154" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2024:0970-1 vom 2024-03-22", "url": "https://lists.suse.com/pipermail/sle-security-updates/2024-March/018191.html" }, { "category": "external", "summary": "Gentoo Linux Security Advisory GLSA-202405-20 vom 2024-05-07", "url": "https://security.gentoo.org/glsa/202405-20" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2024:1846-1 vom 2024-05-29", "url": "https://lists.suse.com/pipermail/sle-security-updates/2024-May/018628.html" }, { "category": "external", "summary": "IBM Security Bulletin 7158789 vom 2024-06-26", "url": "https://www.ibm.com/support/pages/node/7158789" }, { "category": "external", "summary": "Amazon Linux Security Advisory ALAS-2024-2620 vom 2024-08-13", "url": "https://alas.aws.amazon.com/AL2/ALAS-2024-2620.html" }, { "category": "external", "summary": "Debian Security Advisory DLA-3930 vom 2024-10-22", "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00021.html" }, { "category": "external", "summary": "openSUSE Security Update OPENSUSE-SU-2025:14647-1 vom 2025-01-15", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/L4RLODX5GVSAY4VHIRZHWG4EEKI7MMMM/" } ], "source_lang": "en-US", "title": "Red Hat Enterprise Linux: Mehrere Schwachstellen", "tracking": { "current_release_date": "2025-01-15T23:00:00.000+00:00", "generator": { "date": "2025-01-16T09:22:22.870+00:00", "engine": { "name": "BSI-WID", "version": "1.3.10" } }, "id": "WID-SEC-W-2022-0571", "initial_release_date": "2021-11-09T23:00:00.000+00:00", "revision_history": [ { "date": "2021-11-09T23:00:00.000+00:00", "number": "1", "summary": "Initiale Fassung" }, { "date": "2021-11-14T23:00:00.000+00:00", "number": "2", "summary": "Neue Updates von AVAYA aufgenommen" }, { "date": "2021-11-16T23:00:00.000+00:00", "number": "3", "summary": "Neue Updates von Red Hat und Oracle Linux aufgenommen" }, { "date": "2021-11-29T23:00:00.000+00:00", "number": "4", "summary": "Neue Updates von Red Hat aufgenommen" }, { "date": "2021-12-06T23:00:00.000+00:00", "number": "5", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2021-12-13T23:00:00.000+00:00", "number": "6", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2021-12-14T23:00:00.000+00:00", "number": "7", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2021-12-22T23:00:00.000+00:00", "number": "8", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2022-01-17T23:00:00.000+00:00", "number": "9", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2022-01-19T23:00:00.000+00:00", "number": "10", "summary": "Neue Updates von Ubuntu aufgenommen" }, { "date": "2022-01-25T23:00:00.000+00:00", "number": "11", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2022-01-27T23:00:00.000+00:00", "number": "12", "summary": "Neue Updates von Red Hat und Amazon aufgenommen" }, { "date": "2022-02-03T23:00:00.000+00:00", "number": "13", "summary": "Neue Updates von Red Hat aufgenommen" }, { "date": "2022-02-09T23:00:00.000+00:00", "number": "14", "summary": "Referenz(en) aufgenommen: FEDORA-2022-8109B472A3, FEDORA-2022-737E44718A" }, { "date": "2022-02-17T23:00:00.000+00:00", "number": "15", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2022-02-27T23:00:00.000+00:00", "number": "16", "summary": "Neue Updates von Amazon aufgenommen" }, { "date": "2022-03-03T23:00:00.000+00:00", "number": "17", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2022-03-14T23:00:00.000+00:00", "number": "18", "summary": "Neue Updates von Red Hat aufgenommen" }, { "date": "2022-04-26T22:00:00.000+00:00", "number": "19", "summary": "Neue Updates von Ubuntu aufgenommen" }, { "date": "2022-04-27T22:00:00.000+00:00", "number": "20", "summary": "Neue Updates von Oracle Linux aufgenommen" }, { "date": "2022-07-05T22:00:00.000+00:00", "number": "21", "summary": "Neue Updates von Red Hat aufgenommen" }, { "date": "2022-07-20T22:00:00.000+00:00", "number": "22", "summary": "Neue Updates von Amazon aufgenommen" }, { "date": "2022-08-08T22:00:00.000+00:00", "number": "23", "summary": "Neue Updates von Ubuntu aufgenommen" }, { "date": "2022-08-09T22:00:00.000+00:00", "number": "24", "summary": "Neue Updates von Gentoo aufgenommen" }, { "date": "2022-09-04T22:00:00.000+00:00", "number": "25", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2022-09-22T22:00:00.000+00:00", "number": "26", "summary": "Neue Updates von Ubuntu aufgenommen" }, { "date": "2022-10-16T22:00:00.000+00:00", "number": "27", "summary": "Neue Updates von Gentoo und SUSE aufgenommen" }, { "date": "2022-11-01T23:00:00.000+00:00", "number": "28", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2022-11-15T23:00:00.000+00:00", "number": "29", "summary": "Neue Updates von Oracle Linux aufgenommen" }, { "date": "2023-04-05T22:00:00.000+00:00", "number": "30", "summary": "Neue Updates von Amazon aufgenommen" }, { "date": "2023-05-23T22:00:00.000+00:00", "number": "31", "summary": "Neue Updates von Oracle Linux aufgenommen" }, { "date": "2023-06-08T22:00:00.000+00:00", "number": "32", "summary": "Neue Updates von Amazon aufgenommen" }, { "date": "2023-07-18T22:00:00.000+00:00", "number": "33", "summary": "Neue Updates von Red Hat aufgenommen" }, { "date": "2023-09-27T22:00:00.000+00:00", "number": "34", "summary": "Neue Updates von Amazon aufgenommen" }, { "date": "2023-10-19T22:00:00.000+00:00", "number": "35", "summary": "Neue Updates von Amazon aufgenommen" }, { "date": "2023-11-07T23:00:00.000+00:00", "number": "36", "summary": "Neue Updates von Red Hat aufgenommen" }, { "date": "2023-11-14T23:00:00.000+00:00", "number": "37", "summary": "Neue Updates von Red Hat aufgenommen" }, { "date": "2023-12-13T23:00:00.000+00:00", "number": "38", "summary": "Neue Updates von Red Hat aufgenommen" }, { "date": "2024-01-25T23:00:00.000+00:00", "number": "39", "summary": "Neue Updates von Red Hat aufgenommen" }, { "date": "2024-01-30T23:00:00.000+00:00", "number": "40", "summary": "Neue Updates von Red Hat aufgenommen" }, { "date": "2024-02-05T23:00:00.000+00:00", "number": "41", "summary": "Neue Updates von Amazon aufgenommen" }, { "date": "2024-02-19T23:00:00.000+00:00", "number": "42", "summary": "Neue Updates von Amazon aufgenommen" }, { "date": "2024-03-05T23:00:00.000+00:00", "number": "43", "summary": "Neue Updates von Red Hat aufgenommen" }, { "date": "2024-03-24T23:00:00.000+00:00", "number": "44", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2024-05-06T22:00:00.000+00:00", "number": "45", "summary": "Neue Updates von Gentoo aufgenommen" }, { "date": "2024-05-30T22:00:00.000+00:00", "number": "46", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2024-06-25T22:00:00.000+00:00", "number": "47", "summary": "Neue Updates von IBM aufgenommen" }, { "date": "2024-08-13T22:00:00.000+00:00", "number": "48", "summary": "Neue Updates von Amazon aufgenommen" }, { "date": "2024-10-21T22:00:00.000+00:00", "number": "49", "summary": "Neue Updates von Debian aufgenommen" }, { "date": "2025-01-15T23:00:00.000+00:00", "number": "50", "summary": "Neue Updates von openSUSE aufgenommen" } ], "status": "final", "version": "50" } }, "product_tree": { "branches": [ { "branches": [ { "category": "product_name", "name": "Amazon Linux 2", "product": { "name": "Amazon Linux 2", "product_id": "398363", "product_identification_helper": { "cpe": "cpe:/o:amazon:linux_2:-" } } } ], "category": "vendor", "name": "Amazon" }, { "branches": [ { "category": "product_name", "name": "Avaya Aura Experience Portal", "product": { "name": "Avaya Aura Experience Portal", "product_id": "T015519", "product_identification_helper": { "cpe": "cpe:/a:avaya:aura_experience_portal:-" } } } ], "category": "vendor", "name": "Avaya" }, { "branches": [ { "category": "product_name", "name": "Debian Linux", "product": { "name": "Debian Linux", "product_id": "2951", "product_identification_helper": { "cpe": "cpe:/o:debian:debian_linux:-" } } } ], "category": "vendor", "name": "Debian" }, { "branches": [ { "category": "product_name", "name": "Gentoo Linux", "product": { "name": "Gentoo Linux", "product_id": "T012167", "product_identification_helper": { "cpe": "cpe:/o:gentoo:linux:-" } } } ], "category": "vendor", "name": "Gentoo" }, { "branches": [ { "branches": [ { "category": "product_version", "name": "10.0.0-10.0.7.1", "product": { "name": "IBM Security Verify Access 10.0.0-10.0.7.1", "product_id": "T035657", "product_identification_helper": { "cpe": "cpe:/a:ibm:security_verify_access:10.0.0_-_10.0.7.1" } } } ], "category": "product_name", "name": "Security Verify Access" } ], "category": "vendor", "name": "IBM" }, { "branches": [ { "category": "product_name", "name": "Oracle Linux", "product": { "name": "Oracle Linux", "product_id": "T004914", "product_identification_helper": { "cpe": "cpe:/o:oracle:linux:-" } } } ], "category": "vendor", "name": "Oracle" }, { "branches": [ { "branches": [ { "category": "product_name", "name": "Red Hat Enterprise Linux", "product": { "name": "Red Hat Enterprise Linux", "product_id": "67646", "product_identification_helper": { "cpe": "cpe:/o:redhat:enterprise_linux:-" } } }, { "category": "product_version", "name": "8", "product": { "name": "Red Hat Enterprise Linux 8", "product_id": "T014111", "product_identification_helper": { "cpe": "cpe:/o:redhat:enterprise_linux:8" } } } ], "category": "product_name", "name": "Enterprise Linux" }, { "branches": [ { "category": "product_version_range", "name": "Data Foundation \u003c4.12.10", "product": { "name": "Red Hat OpenShift Data Foundation \u003c4.12.10", "product_id": "T031698" } }, { "category": "product_version", "name": "Data Foundation 4.12.10", "product": { "name": "Red Hat OpenShift Data Foundation 4.12.10", "product_id": "T031698-fixed", "product_identification_helper": { "cpe": "cpe:/a:redhat:openshift:data_foundation__4.12.10" } } } ], "category": "product_name", "name": "OpenShift" } ], "category": "vendor", "name": "Red Hat" }, { "branches": [ { "category": "product_name", "name": "SUSE Linux", "product": { "name": "SUSE Linux", "product_id": "T002207", "product_identification_helper": { "cpe": "cpe:/o:suse:suse_linux:-" } } }, { "category": "product_name", "name": "SUSE openSUSE", "product": { "name": "SUSE openSUSE", "product_id": "T027843", "product_identification_helper": { "cpe": "cpe:/o:suse:opensuse:-" } } } ], "category": "vendor", "name": "SUSE" }, { "branches": [ { "category": "product_name", "name": "Ubuntu Linux", "product": { "name": "Ubuntu Linux", "product_id": "T000126", "product_identification_helper": { "cpe": "cpe:/o:canonical:ubuntu_linux:-" } } } ], "category": "vendor", "name": "Ubuntu" } ] }, "vulnerabilities": [ { "cve": "CVE-2019-17594", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2019-17594" }, { "cve": "CVE-2019-17595", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2019-17595" }, { "cve": "CVE-2019-18218", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2019-18218" }, { "cve": "CVE-2019-19004", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2019-19004" }, { "cve": "CVE-2019-19005", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2019-19005" }, { "cve": "CVE-2020-12762", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2020-12762" }, { "cve": "CVE-2020-17541", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2020-17541" }, { "cve": "CVE-2020-18442", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2020-18442" }, { "cve": "CVE-2020-24370", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2020-24370" }, { "cve": "CVE-2020-8037", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2020-8037" }, { "cve": "CVE-2021-20095", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-20095" }, { "cve": "CVE-2021-28957", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-28957" }, { "cve": "CVE-2021-29922", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-29922" }, { "cve": "CVE-2021-3200", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-3200" }, { "cve": "CVE-2021-3445", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-3445" }, { "cve": "CVE-2021-3481", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-3481" }, { "cve": "CVE-2021-3565", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-3565" }, { "cve": "CVE-2021-3571", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-3571" }, { "cve": "CVE-2021-3572", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-3572" }, { "cve": "CVE-2021-3602", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-3602" }, { "cve": "CVE-2021-36084", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-36084" }, { "cve": "CVE-2021-36085", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-36085" }, { "cve": "CVE-2021-36086", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-36086" }, { "cve": "CVE-2021-36087", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-36087" }, { "cve": "CVE-2021-42771", "notes": [ { "category": "description", "text": "In Red Hat Enterprise Linux existieren mehrere Schwachstellen. Die Fehler existieren in den Komponenten python-lxml, qt5, python-babel, container-tools:2.0, container-tools:3.0, tcpdump, rust-toolset, libjpeg-turbo, zziplib, linuxptp, file, json-c, libsolv, tpm2-tools, ncurses, python-pip, dnf, dnf-plugins-core, libdnf, lua, libsepol und autotrace. Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuf\u00fchren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, beliebigen Code auszuf\u00fchren, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuf\u00fchren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion und erh\u00f6hte Rechte." } ], "product_status": { "known_affected": [ "T035657", "T015519", "T031698", "2951", "T002207", "67646", "T000126", "T027843", "398363", "T012167", "T004914", "T014111" ] }, "release_date": "2021-11-09T23:00:00.000+00:00", "title": "CVE-2021-42771" } ] }
fkie_cve-2020-8037
Vulnerability from fkie_nvd
Published
2020-11-04 18:15
Modified
2024-11-21 05:38
Severity ?
Summary
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
References
▶ | URL | Tags | |
---|---|---|---|
security@tcpdump.org | http://seclists.org/fulldisclosure/2021/Apr/51 | Mailing List, Third Party Advisory | |
security@tcpdump.org | https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231 | Patch, Third Party Advisory | |
security@tcpdump.org | https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html | Mailing List, Third Party Advisory | |
security@tcpdump.org | https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2MX34MJIUJQGL6CMEPLTKFOOOC3CJ4Z/ | ||
security@tcpdump.org | https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWDBONZVLC6BAOR2KM376DJCM4H3FERV/ | ||
security@tcpdump.org | https://support.apple.com/kb/HT212325 | Third Party Advisory | |
security@tcpdump.org | https://support.apple.com/kb/HT212326 | Third Party Advisory | |
security@tcpdump.org | https://support.apple.com/kb/HT212327 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://seclists.org/fulldisclosure/2021/Apr/51 | Mailing List, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231 | Patch, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html | Mailing List, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2MX34MJIUJQGL6CMEPLTKFOOOC3CJ4Z/ | ||
af854a3a-2127-422b-91ae-364da2661108 | https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWDBONZVLC6BAOR2KM376DJCM4H3FERV/ | ||
af854a3a-2127-422b-91ae-364da2661108 | https://support.apple.com/kb/HT212325 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://support.apple.com/kb/HT212326 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://support.apple.com/kb/HT212327 | Third Party Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
tcpdump | tcpdump | 4.9.3 | |
debian | debian_linux | 9.0 | |
fedoraproject | fedora | 32 | |
fedoraproject | fedora | 33 | |
apple | mac_os_x | * | |
apple | mac_os_x | * | |
apple | mac_os_x | 10.14.6 | |
apple | mac_os_x | 10.14.6 | |
apple | mac_os_x | 10.14.6 | |
apple | mac_os_x | 10.14.6 | |
apple | mac_os_x | 10.14.6 | |
apple | mac_os_x | 10.14.6 | |
apple | mac_os_x | 10.14.6 | |
apple | mac_os_x | 10.14.6 | |
apple | mac_os_x | 10.14.6 | |
apple | mac_os_x | 10.14.6 | |
apple | mac_os_x | 10.14.6 | |
apple | mac_os_x | 10.15.7 | |
apple | mac_os_x | 10.15.7 | |
apple | mac_os_x | 10.15.7 | |
apple | mac_os_x | 10.15.7 | |
apple | macos | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:tcpdump:tcpdump:4.9.3:*:*:*:*:*:*:*", "matchCriteriaId": "50B2D924-9D76-425D-828F-222F74F9F7AF", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*", "matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*", "matchCriteriaId": "36D96259-24BD-44E2-96D9-78CE1D41F956", "vulnerable": true }, { "criteria": "cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*", "matchCriteriaId": "E460AA51-FCDA-46B9-AE97-E6676AA5E194", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*", "matchCriteriaId": "B0E97851-4DFF-4852-A339-183331F4ACBC", "versionEndExcluding": "10.14.6", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*", "matchCriteriaId": "DB8A73F8-3074-4B32-B9F6-343B6B1988C5", "versionEndExcluding": "10.15.7", "versionStartIncluding": "10.15", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.14.6:-:*:*:*:*:*:*", "matchCriteriaId": "693E7DAE-BBF0-4D48-9F8A-20DDBD4AAC0C", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-001:*:*:*:*:*:*", "matchCriteriaId": "CFE26ECC-A2C2-4501-9950-510DE0E1BD86", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-002:*:*:*:*:*:*", "matchCriteriaId": "26108BEF-0847-4AB0-BD98-35344DFA7835", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-001:*:*:*:*:*:*", "matchCriteriaId": "0FD3467D-7679-479F-9C0B-A93F7CD0929D", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-002:*:*:*:*:*:*", "matchCriteriaId": "D4C6098E-EDBD-4A85-8282-B2E9D9333872", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-003:*:*:*:*:*:*", "matchCriteriaId": "518BB47B-DD76-4E8C-9F10-7EBC1E146191", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-004:*:*:*:*:*:*", "matchCriteriaId": "63940A55-D851-46EB-9668-D82BEFC1FE95", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-005:*:*:*:*:*:*", "matchCriteriaId": "68C7A97A-3801-44FA-96CA-10298FA39883", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-006:*:*:*:*:*:*", "matchCriteriaId": "6D69914D-46C7-4A0E-A075-C863C1692D33", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-007:*:*:*:*:*:*", "matchCriteriaId": "9CDB4476-B521-43E4-A129-8718A8E0A8CD", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2021-001:*:*:*:*:*:*", "matchCriteriaId": "9D072B77-BE3F-4A2E-B66A-E2C8DC3781E4", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:*", "matchCriteriaId": "A654B8A2-FC30-4171-B0BB-366CD7ED4B6A", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:*", "matchCriteriaId": "F1F4BF7F-90D4-4668-B4E6-B06F4070F448", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-001:*:*:*:*:*:*", "matchCriteriaId": "0F441A43-1669-478D-9EC8-E96882DE4F9F", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:supplemental_update:*:*:*:*:*:*", "matchCriteriaId": "C1C795B9-E58D-467C-83A8-2D45C792292F", "vulnerable": true }, { "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*", "matchCriteriaId": "4E699CCC-31F5-458E-A59C-79B3AF143747", "versionEndExcluding": "11.3", "versionStartIncluding": "11.0", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory." }, { "lang": "es", "value": "El ppp decapsulator en tcpdump versi\u00f3n 4.9.3 puede ser convencido para que asigne una gran cantidad de memoria" } ], "id": "CVE-2020-8037", "lastModified": "2024-11-21T05:38:16.200", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 5.0, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 3.6, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2020-11-04T18:15:20.843", "references": [ { "source": "security@tcpdump.org", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://seclists.org/fulldisclosure/2021/Apr/51" }, { "source": "security@tcpdump.org", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231" }, { "source": "security@tcpdump.org", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html" }, { "source": "security@tcpdump.org", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2MX34MJIUJQGL6CMEPLTKFOOOC3CJ4Z/" }, { "source": "security@tcpdump.org", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWDBONZVLC6BAOR2KM376DJCM4H3FERV/" }, { "source": "security@tcpdump.org", "tags": [ "Third Party Advisory" ], "url": "https://support.apple.com/kb/HT212325" }, { "source": "security@tcpdump.org", "tags": [ "Third Party Advisory" ], "url": "https://support.apple.com/kb/HT212326" }, { "source": "security@tcpdump.org", "tags": [ "Third Party Advisory" ], "url": "https://support.apple.com/kb/HT212327" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://seclists.org/fulldisclosure/2021/Apr/51" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2MX34MJIUJQGL6CMEPLTKFOOOC3CJ4Z/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWDBONZVLC6BAOR2KM376DJCM4H3FERV/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://support.apple.com/kb/HT212325" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://support.apple.com/kb/HT212326" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://support.apple.com/kb/HT212327" } ], "sourceIdentifier": "security@tcpdump.org", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-770" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
ghsa-qggh-75q9-j3rf
Vulnerability from github
Published
2022-05-24 17:33
Modified
2022-05-24 17:33
VLAI Severity ?
Details
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
{ "affected": [], "aliases": [ "CVE-2020-8037" ], "database_specific": { "cwe_ids": [ "CWE-770" ], "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-11-04T18:15:00Z", "severity": "HIGH" }, "details": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.", "id": "GHSA-qggh-75q9-j3rf", "modified": "2022-05-24T17:33:10Z", "published": "2022-05-24T17:33:10Z", "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-8037" }, { "type": "WEB", "url": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231" }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F2MX34MJIUJQGL6CMEPLTKFOOOC3CJ4Z" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LWDBONZVLC6BAOR2KM376DJCM4H3FERV" }, { "type": "WEB", "url": "https://support.apple.com/kb/HT212325" }, { "type": "WEB", "url": "https://support.apple.com/kb/HT212326" }, { "type": "WEB", "url": "https://support.apple.com/kb/HT212327" }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2021/Apr/51" } ], "schema_version": "1.4.0", "severity": [] }
gsd-2020-8037
Vulnerability from gsd
Modified
2023-12-13 01:21
Details
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
Aliases
Aliases
{ "GSD": { "alias": "CVE-2020-8037", "description": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.", "id": "GSD-2020-8037", "references": [ "https://www.suse.com/security/cve/CVE-2020-8037.html", "https://access.redhat.com/errata/RHSA-2021:4236", "https://advisories.mageia.org/CVE-2020-8037.html", "https://ubuntu.com/security/CVE-2020-8037", "https://linux.oracle.com/cve/CVE-2020-8037.html" ] }, "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2020-8037" ], "details": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.", "id": "GSD-2020-8037", "modified": "2023-12-13T01:21:54.379894Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "security@tcpdump.org", "DATE_PUBLIC": "2020-04-21T00:00:00.000Z", "ID": "CVE-2020-8037", "STATE": "PUBLIC", "TITLE": "ppp decapsulator can be convinced to allocate a large amount of memory" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "tcpdump", "version": { "version_data": [ { "version_value": "4.9.3" } ] } } ] }, "vendor_name": "The TCPdump Group" } ] } }, "credit": [ { "lang": "eng", "value": "Hardik Shah" } ], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "memory overallocation error" } ] } ] }, "references": { "reference_data": [ { "name": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231", "refsource": "MISC", "url": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231" }, { "name": "[debian-lts-announce] 20201110 [SECURITY] [DLA 2444-1] tcpdump security update", "refsource": "MLIST", "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html" }, { "name": "FEDORA-2020-fae2e1f2bc", "refsource": "FEDORA", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LWDBONZVLC6BAOR2KM376DJCM4H3FERV/" }, { "name": "FEDORA-2020-c5e78886d6", "refsource": "FEDORA", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F2MX34MJIUJQGL6CMEPLTKFOOOC3CJ4Z/" }, { "name": "20210427 APPLE-SA-2021-04-26-3 Security Update 2021-002 Catalina", "refsource": "FULLDISC", "url": "http://seclists.org/fulldisclosure/2021/Apr/51" }, { "name": "https://support.apple.com/kb/HT212325", "refsource": "CONFIRM", "url": "https://support.apple.com/kb/HT212325" }, { "name": "https://support.apple.com/kb/HT212326", "refsource": "CONFIRM", "url": "https://support.apple.com/kb/HT212326" }, { "name": "https://support.apple.com/kb/HT212327", "refsource": "CONFIRM", "url": "https://support.apple.com/kb/HT212327" } ] } }, "nvd.nist.gov": { "configurations": { "CVE_data_version": "4.0", "nodes": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:tcpdump:tcpdump:4.9.3:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true } ], "operator": "OR" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true } ], "operator": "OR" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true } ], "operator": "OR" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndExcluding": "10.14.6", "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.14.6:-:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-001:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-002:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-001:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-002:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-003:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-004:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-005:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-006:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2020-007:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2021-001:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndExcluding": "10.15.7", "versionStartIncluding": "10.15", "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-001:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:10.15.7:supplemental_update:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndExcluding": "11.3", "versionStartIncluding": "11.0", "vulnerable": true } ], "operator": "OR" } ] }, "cve": { "CVE_data_meta": { "ASSIGNER": "security@tcpdump.org", "ID": "CVE-2020-8037" }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "en", "value": "The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "en", "value": "CWE-770" } ] } ] }, "references": { "reference_data": [ { "name": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231", "refsource": "MISC", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/the-tcpdump-group/tcpdump/commit/32027e199368dad9508965aae8cd8de5b6ab5231" }, { "name": "[debian-lts-announce] 20201110 [SECURITY] [DLA 2444-1] tcpdump security update", "refsource": "MLIST", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00018.html" }, { "name": "FEDORA-2020-fae2e1f2bc", "refsource": "FEDORA", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LWDBONZVLC6BAOR2KM376DJCM4H3FERV/" }, { "name": "FEDORA-2020-c5e78886d6", "refsource": "FEDORA", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F2MX34MJIUJQGL6CMEPLTKFOOOC3CJ4Z/" }, { "name": "https://support.apple.com/kb/HT212327", "refsource": "CONFIRM", "tags": [ "Third Party Advisory" ], "url": "https://support.apple.com/kb/HT212327" }, { "name": "https://support.apple.com/kb/HT212326", "refsource": "CONFIRM", "tags": [ "Third Party Advisory" ], "url": "https://support.apple.com/kb/HT212326" }, { "name": "https://support.apple.com/kb/HT212325", "refsource": "CONFIRM", "tags": [ "Third Party Advisory" ], "url": "https://support.apple.com/kb/HT212325" }, { "name": "20210427 APPLE-SA-2021-04-26-3 Security Update 2021-002 Catalina", "refsource": "FULLDISC", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://seclists.org/fulldisclosure/2021/Apr/51" } ] } }, "impact": { "baseMetricV2": { "acInsufInfo": false, "cvssV2": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 5.0, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "severity": "MEDIUM", "userInteractionRequired": false }, "baseMetricV3": { "cvssV3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 3.6 } }, "lastModifiedDate": "2021-05-05T13:12Z", "publishedDate": "2020-11-04T18:15Z" } } }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…