Stack-based buffer over-read in Tcpdump - CVE-2018-19519

 

Stack-based buffer over-read in Tcpdump - CVE-2018-19519

Published: November 27, 2018 / Updated: January 1, 2023


Vulnerability identifier: #VU16161
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19519
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information or cause DoS condition.

The vulnerability exists in the print_prefix function, as defined in the print-hncp.c source code file of the affected software due to insufficient initialization of the buf variable. A remote attacker can trick the victim into execution of the tcpdumpcommand on a .pcap file that submits malicious input, trigger a stack-based buffer overread and access sensitive memory information or cause a DoS condition. 


Affected software

Tcpdump
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Opensuse
Fedora
Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Policy Secure (formerly Pulse Policy Secure)
tcpdump (Red Hat package)
tcpdump

How to mitigate CVE-2018-19519

Install update from vendor's website.

Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 9.1R8
Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 9.1R8
tcpdump (Red Hat package) - update to 4.9.2-6.el8
tcpdump - addressed in versions 4.9.3-1.fc29, 4.9.3-1.fc30, 4.9.3-1.fc31

External References

Related Security Bulletins