Out-of-bounds read in libpcap - CVE-2018-16301
Published: October 21, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in libpcap when during pcapng reading. A remote attacker can pass specially crafted data to the application that uses the affected library, trigger out-of-bounds read error and read contents of memory on the system or crash the application.
Affected software
cflinuxfs3
EMC ECS
Isolation Segment
VMware Tanzu Application Service for VMs
Tcpdump
tcpdump (Alpine package)
libpcap
tcpdump-debuginfo
tcpdump
tcpdump-debugsource
tcpdump (Ubuntu package)
tcpdump-help
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
Oracle Solaris
SUSE Linux Enterprise Server for SAP
Slackware Linux
Opensuse
Ubuntu
openEuler
Fedora
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
How to mitigate CVE-2018-16301
cflinuxfs3 - update to 0.283.0
Isolation Segment - addressed in versions 2.7.44, 2.10.24, 2.11.13, 2.12.7
VMware Tanzu Application Service for VMs - addressed in versions 2.7.49, 2.10.31, 2.11.19, 2.12.12
Tcpdump - update to 4.9.3
tcpdump (Alpine package) - update to 4.9.3-r0
libpcap - addressed in versions 1.9.1-1.fc29, 1.9.1-1.fc30, 1.9.1-1.fc31
EMC ECS - update to 3.7.0.2
tcpdump-debuginfo - addressed in versions 3.9.8-1.30.19.1, 4.9.2-14.20.1
tcpdump - addressed in versions 3.9.8-1.30.19.1, 4.9.2-14.20.1
tcpdump-debugsource - addressed in versions 3.9.8-1.30.19.1, 4.9.2-14.20.1
tcpdump (Ubuntu package) - addressed in versions 4.9.3-0ubuntu0.18.04.2, 4.9.3-4ubuntu0.1, 4.9.30ubuntu0.16.04.1+esm1
tcpdump - addressed in versions 4.9.3-1.fc29, 4.9.3-1.fc30, 4.9.3-1.fc31
tcpdump-help - update to 4.9.3-6
tcpdump-debugsource - update to 4.9.3-6
tcpdump - update to 4.9.3-6
tcpdump-debuginfo - update to 4.9.3-6
Dell EMC Unity Operating Environment (OE) - addressed in versions 5.0.3.0.5.014, 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - addressed in versions 5.0.3.0.5.014, 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
External References
Related Security Bulletins
- OpenSUSE Linux update for libpcap
- OpenSUSE Linux update for libpcap
- Multiple vulnerabilities in libpcap
- OpenSUSE Linux update for tcpdump
- OpenSUSE Linux update for tcpdump
- Multiple vulnerabilities in Tcpdump
- Slackware Linux update for tcpdump
- Oracle Solaris update for third party packages
- Out-of-bounds read in tcpdump (Alpine package)
- Ubuntu update for tcpdump
- Ubuntu update for tcpdump
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- VMware Tanzu products update for tcpdump
- Multiple vulnerabilities in Dell Elastic Cloud Storage (ECS)
- SUSE update for tcpdump
- SUSE update for tcpdump
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- openEuler 20.03 LTS SP3 update for tcpdump
- openEuler 20.03 LTS SP1 update for tcpdump
- Fedora 30 update for libpcap
- Fedora 31 update for libpcap
- Fedora 29 update for libpcap
- Fedora 31 update for tcpdump
- Fedora 30 update for tcpdump
- Fedora 29 update for tcpdump
- Dell EMC Unity update for third-party components