{"affected":[{"ecosystem_specific":{"binaries":[{"tcpdump":"3.9.8-1.30.13.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Point of Sale 11 SP3","name":"tcpdump","purl":"pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.9.8-1.30.13.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"tcpdump":"3.9.8-1.30.13.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4-LTSS","name":"tcpdump","purl":"pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.9.8-1.30.13.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for tcpdump fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2017-12995: Fixed an infinite loop in the DNS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12893: Fixed a buffer over-read in the SMB/CIFS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12894: Fixed a buffer over-read in several protocol parsers that allowed remote DoS (bsc#1057247).\n- CVE-2017-12896: Fixed a buffer over-read in the ISAKMP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12897: Fixed a buffer over-read in the ISO CLNS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12898: Fixed a buffer over-read in the NFS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12899: Fixed a buffer over-read in the DECnet parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12900: Fixed a buffer over-read in the in several protocol parsers that allowed remote DoS (bsc#1057247).\n- CVE-2017-12901: Fixed a buffer over-read in the EIGRP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12902: Fixed a buffer over-read in the Zephyr parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12985: Fixed a buffer over-read in the IPv6 parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12986: Fixed a buffer over-read in the IPv6 routing header parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12987: Fixed a buffer over-read in the 802.11 parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12988: Fixed a buffer over-read in the telnet parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12991: Fixed a buffer over-read in the BGP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12992: Fixed a buffer over-read in the RIPng parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12993: Fixed a buffer over-read in the Juniper protocols parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12996: Fixed a buffer over-read in the PIMv2 parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12998: Fixed a buffer over-read in the IS-IS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-12999: Fixed a buffer over-read in the IS-IS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13001: Fixed a buffer over-read in the NFS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13002: Fixed a buffer over-read in the AODV parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13003: Fixed a buffer over-read in the LMP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13004: Fixed a buffer over-read in the Juniper protocols parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13005: Fixed a buffer over-read in the NFS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13006: Fixed a buffer over-read in the L2TP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13008: Fixed a buffer over-read in the IEEE 802.11 parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13009: Fixed a buffer over-read in the IPv6 mobility parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13010: Fixed a buffer over-read in the BEEP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13012: Fixed a buffer over-read in the ICMP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13013: Fixed a buffer over-read in the ARP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13014: Fixed a buffer over-read in the White Board protocol parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13016: Fixed a buffer over-read in the ISO ES-IS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13017: Fixed a buffer over-read in the DHCPv6 parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13018: Fixed a buffer over-read in the PGM parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13019: Fixed a buffer over-read in the PGM parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13021: Fixed a buffer over-read in the ICMPv6 parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13022: Fixed a buffer over-read in the IP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13023: Fixed a buffer over-read in the IPv6 mobility parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13024: Fixed a buffer over-read in the IPv6 mobility parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13025: Fixed a buffer over-read in the IPv6 mobility parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13027: Fixed a buffer over-read in the LLDP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13028: Fixed a buffer over-read in the BOOTP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13029: Fixed a buffer over-read in the PPP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13030: Fixed a buffer over-read in the PIM parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13031: Fixed a buffer over-read in the IPv6 fragmentation header parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13032: Fixed a buffer over-read in the RADIUS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13034: Fixed a buffer over-read in the PGM parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13035: Fixed a buffer over-read in the ISO IS-IS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13036: Fixed a buffer over-read in the OSPFv3 parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13037: Fixed a buffer over-read in the IP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13038: Fixed a buffer over-read in the PPP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13041: Fixed a buffer over-read in the ICMPv6 parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13047: Fixed a buffer over-read in the ISO ES-IS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13048: Fixed a buffer over-read in the RSVP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13049: Fixed a buffer over-read in the Rx protocol parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13051: Fixed a buffer over-read in the RSVP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13053: Fixed a buffer over-read in the BGP parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13055: Fixed a buffer over-read in the ISO IS-IS parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13687: Fixed a buffer over-read in the Cisco HDLC parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13688: Fixed a buffer over-read in the OLSR parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13689: Fixed a buffer over-read in the IKEv1 parser that allowed remote DoS (bsc#1057247).\n- CVE-2017-13725: Fixed a buffer over-read in the IPv6 routing header parser that allowed remote DoS (bsc#1057247).\n- CVE-2018-10103: Fixed a mishandling of the printing of SMB data (bsc#1153098).\n- CVE-2018-10105: Fixed a mishandling of the printing of SMB data (bsc#1153098).\n- CVE-2018-14461: Fixed a buffer over-read in print-ldp.c:ldp_tlv_print (bsc#1153098).\n- CVE-2018-14462: Fixed a buffer over-read in print-icmp.c:icmp_print (bsc#1153098).\n- CVE-2018-14463: Fixed a buffer over-read in print-vrrp.c:vrrp_print (bsc#1153098).\n- CVE-2018-14464: Fixed a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs (bsc#1153098).\n- CVE-2018-14465: Fixed a buffer over-read in print-rsvp.c:rsvp_obj_print (bsc#1153098).\n- CVE-2018-14466: Fixed a buffer over-read in print-rx.c:rx_cache_find (bsc#1153098).\n- CVE-2018-14467: Fixed a buffer over-read in print-bgp.c:bgp_capabilities_print (bsc#1153098).\n- CVE-2018-14468: Fixed a buffer over-read in print-fr.c:mfr_print (bsc#1153098).\n- CVE-2018-14469: Fixed a buffer over-read in print-isakmp.c:ikev1_n_print (bsc#1153098).\n- CVE-2018-14881: Fixed a buffer over-read in the BGP parser (bsc#1153098).\n- CVE-2018-14882: Fixed a buffer over-read in the ICMPv6 parser (bsc#1153098).\n- CVE-2018-16229: Fixed a buffer over-read in the DCCP parser (bsc#1153098).\n- CVE-2018-16230: Fixed a buffer over-read in the BGP parser in print-bgp.c:bgp_attr_print (bsc#1153098).\n- CVE-2018-16300: Fixed an unlimited recursion in the BGP parser that allowed denial-of-service by stack consumption (bsc#1153098).\n- CVE-2018-16301: Fixed a buffer overflow (bsc#1153332 bsc#1153098).\n- CVE-2018-16451: Fixed several buffer over-reads in print-smb.c:print_trans() for \\MAILSLOT\\BROWSE and \\PIPE\\LANMAN (bsc#1153098).\n- CVE-2018-16452: Fixed a stack exhaustion in smbutil.c:smb_fdata (bsc#1153098).\n- CVE-2019-15166: Fixed a bounds check in lmp_print_data_link_subobjs (bsc#1153098).\n","id":"SUSE-SU-2019:14191-1","modified":"2019-10-15T09:18:48Z","published":"2019-10-15T09:18:48Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-201914191-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1057247"},{"type":"REPORT","url":"https://bugzilla.suse.com/1153098"},{"type":"REPORT","url":"https://bugzilla.suse.com/1153332"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12893"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12894"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12896"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12897"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12898"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12899"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12900"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12901"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12902"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12985"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12988"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12991"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12992"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12993"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12995"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12996"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12998"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12999"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13001"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13002"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13003"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13004"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13005"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13006"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13008"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13009"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13012"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13013"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13014"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13016"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13017"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13018"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13019"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13021"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13022"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13024"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13025"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13027"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13028"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13029"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13030"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13031"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13032"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13034"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13035"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13036"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13037"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13038"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13041"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13047"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13048"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13051"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13053"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13055"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13687"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13688"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13689"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-10103"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-10105"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14461"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14462"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14463"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14465"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14466"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14467"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14468"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14881"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14882"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16229"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16230"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16300"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16301"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16451"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16452"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-15166"}],"related":["CVE-2017-12893","CVE-2017-12894","CVE-2017-12896","CVE-2017-12897","CVE-2017-12898","CVE-2017-12899","CVE-2017-12900","CVE-2017-12901","CVE-2017-12902","CVE-2017-12985","CVE-2017-12986","CVE-2017-12987","CVE-2017-12988","CVE-2017-12991","CVE-2017-12992","CVE-2017-12993","CVE-2017-12995","CVE-2017-12996","CVE-2017-12998","CVE-2017-12999","CVE-2017-13001","CVE-2017-13002","CVE-2017-13003","CVE-2017-13004","CVE-2017-13005","CVE-2017-13006","CVE-2017-13008","CVE-2017-13009","CVE-2017-13010","CVE-2017-13012","CVE-2017-13013","CVE-2017-13014","CVE-2017-13016","CVE-2017-13017","CVE-2017-13018","CVE-2017-13019","CVE-2017-13021","CVE-2017-13022","CVE-2017-13023","CVE-2017-13024","CVE-2017-13025","CVE-2017-13027","CVE-2017-13028","CVE-2017-13029","CVE-2017-13030","CVE-2017-13031","CVE-2017-13032","CVE-2017-13034","CVE-2017-13035","CVE-2017-13036","CVE-2017-13037","CVE-2017-13038","CVE-2017-13041","CVE-2017-13047","CVE-2017-13048","CVE-2017-13049","CVE-2017-13051","CVE-2017-13053","CVE-2017-13055","CVE-2017-13687","CVE-2017-13688","CVE-2017-13689","CVE-2017-13725","CVE-2018-10103","CVE-2018-10105","CVE-2018-14461","CVE-2018-14462","CVE-2018-14463","CVE-2018-14464","CVE-2018-14465","CVE-2018-14466","CVE-2018-14467","CVE-2018-14468","CVE-2018-14469","CVE-2018-14881","CVE-2018-14882","CVE-2018-16229","CVE-2018-16230","CVE-2018-16300","CVE-2018-16301","CVE-2018-16451","CVE-2018-16452","CVE-2019-15166"],"summary":"Security update for tcpdump","upstream":["CVE-2017-12893","CVE-2017-12894","CVE-2017-12896","CVE-2017-12897","CVE-2017-12898","CVE-2017-12899","CVE-2017-12900","CVE-2017-12901","CVE-2017-12902","CVE-2017-12985","CVE-2017-12986","CVE-2017-12987","CVE-2017-12988","CVE-2017-12991","CVE-2017-12992","CVE-2017-12993","CVE-2017-12995","CVE-2017-12996","CVE-2017-12998","CVE-2017-12999","CVE-2017-13001","CVE-2017-13002","CVE-2017-13003","CVE-2017-13004","CVE-2017-13005","CVE-2017-13006","CVE-2017-13008","CVE-2017-13009","CVE-2017-13010","CVE-2017-13012","CVE-2017-13013","CVE-2017-13014","CVE-2017-13016","CVE-2017-13017","CVE-2017-13018","CVE-2017-13019","CVE-2017-13021","CVE-2017-13022","CVE-2017-13023","CVE-2017-13024","CVE-2017-13025","CVE-2017-13027","CVE-2017-13028","CVE-2017-13029","CVE-2017-13030","CVE-2017-13031","CVE-2017-13032","CVE-2017-13034","CVE-2017-13035","CVE-2017-13036","CVE-2017-13037","CVE-2017-13038","CVE-2017-13041","CVE-2017-13047","CVE-2017-13048","CVE-2017-13049","CVE-2017-13051","CVE-2017-13053","CVE-2017-13055","CVE-2017-13687","CVE-2017-13688","CVE-2017-13689","CVE-2017-13725","CVE-2018-10103","CVE-2018-10105","CVE-2018-14461","CVE-2018-14462","CVE-2018-14463","CVE-2018-14464","CVE-2018-14465","CVE-2018-14466","CVE-2018-14467","CVE-2018-14468","CVE-2018-14469","CVE-2018-14881","CVE-2018-14882","CVE-2018-16229","CVE-2018-16230","CVE-2018-16300","CVE-2018-16301","CVE-2018-16451","CVE-2018-16452","CVE-2019-15166"]}