Amazon Linux 1 Security Advisory: ALAS-2022-1641
Advisory Release Date: 2022-12-01 17:33 Pacific
Advisory Updated Date: 2022-12-10 00:46 Pacific
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463. (CVE-2019-15167)
Affected Packages:
tcpdump
Issue Correction:
Run yum update tcpdump to update your system.
i686:
tcpdump-4.9.2-4.24.amzn1.i686
tcpdump-debuginfo-4.9.2-4.24.amzn1.i686
src:
tcpdump-4.9.2-4.24.amzn1.src
x86_64:
tcpdump-debuginfo-4.9.2-4.24.amzn1.x86_64
tcpdump-4.9.2-4.24.amzn1.x86_64