Amazon Linux 1 Security Advisory: ALAS-2015-557
Advisory Release Date: 2015-07-07 12:31 Pacific
Advisory Updated Date: 2015-07-07 22:25 Pacific
Integer signedness error in the mobility_opt_print function in the IPv6 mobility printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) or possibly execute arbitrary code via a negative length value. (CVE-2015-0261)
The osi_print_cksum function in print-isoclns.c in the ethernet printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) length, (2) offset, or (3) base pointer checksum value. (CVE-2015-2154)
Affected Packages:
tcpdump
Issue Correction:
Run yum update tcpdump to update your system.
i686:
tcpdump-4.0.0-3.20090921gitdf3cb4.2.10.amzn1.i686
tcpdump-debuginfo-4.0.0-3.20090921gitdf3cb4.2.10.amzn1.i686
src:
tcpdump-4.0.0-3.20090921gitdf3cb4.2.10.amzn1.src
x86_64:
tcpdump-debuginfo-4.0.0-3.20090921gitdf3cb4.2.10.amzn1.x86_64
tcpdump-4.0.0-3.20090921gitdf3cb4.2.10.amzn1.x86_64