Summary
Several vulnerabilities have been
discovered in tcpdump, a command-line network traffic analyzer. These vulnerabilities might result in denial of service, leaking sensitive information from memory or, potentially, execution of arbitrary code.
Solution
For the stable distribution (wheezy),
these problems have been fixed in version 4.3.0-1+deb7u1.
For the upcoming stable distribution (jessie), these problems have been fixed in version 4.6.2-3.
For the unstable distribution (sid), these problems have been fixed in version 4.6.2-3.
We recommend that you upgrade your tcpdump packages.
Insight
This program allows you to dump
the traffic on a network. tcpdump is able to examine IPv4, ICMPv4, IPv6, ICMPv6, UDP, TCP, SNMP, AFS BGP, RIP, PIM, DVMRP, IGMP, SMB, OSPF, NFS and many other packet types.
Affected
tcpdump on Debian Linux
Detection
This check tests the installed software
version using the apt package manager.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2014-8767, CVE-2014-8769, CVE-2014-9140 -
CVSS Base Score: 6.4
AV:N/AC:L/Au:N/C:P/I:N/A:P
Related Vulnerabilities