Bug 24077 - tcpdump new security issue CVE-2018-19519
Summary: tcpdump new security issue CVE-2018-19519
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA6-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2018-12-26 03:44 CET by David Walser
Modified: 2018-12-28 11:17 CET (History)
5 users (show)

See Also:
Source RPM: tcpdump-4.9.2-2.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2018-12-26 03:44:22 CET
openSUSE has issued an advisory on December 15:
https://lists.opensuse.org/opensuse-updates/2018-12/msg00081.html

Mageia 6 is also affected.
David Walser 2018-12-26 03:44:29 CET

Whiteboard: (none) => MGA6TOO

Comment 1 David GEIGER 2018-12-26 05:11:50 CET
Fixed both Cauldron and mga6!

CC: (none) => geiger.david68210

Comment 2 Marja Van Waes 2018-12-26 08:13:33 CET
(In reply to David GEIGER from comment #1)
> Fixed both Cauldron and mga6!

Thanks, David :-)

Assigning to all packagers collectively for the still needed advisory, since there is no registered maintainer for this package.

Assignee: bugsquad => pkg-bugs
Whiteboard: MGA6TOO => (none)
CC: (none) => marja11
Version: Cauldron => 6

Comment 3 David Walser 2018-12-26 15:53:54 CET
Advisory:
========================

Updated tcpdump package fixes security vulnerability:

Fixed a stack-based buffer over-read in the print_prefix function
(CVE-2018-19519).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19519
https://lists.opensuse.org/opensuse-updates/2018-12/msg00081.html
========================

Updated packages in core/updates_testing:
========================
tcpdump-4.9.2-1.1.mga6

from tcpdump-4.9.2-1.1.mga6.src.rpm

Assignee: pkg-bugs => qa-bugs

Comment 4 Brian Rockwell 2018-12-27 01:26:22 CET
To satisfy dependencies, the following package(s) also need to be installed:

- lib64smi2-0.5.0-2.mga6.x86_64
- libsmi-mibs-std-0.5.0-2.mga6.x86_64
- smi-tools-0.5.0-2.mga6.x86_64

17MB of additional disk space will be used.


I ran 

tcpdump -tttt

and watched the network activity in the network.

Working as designed

CC: (none) => brtians1
Whiteboard: (none) => MGA6-64-OK

Comment 5 Lewis Smith 2018-12-27 20:38:56 CET
Thanks Brian. Validating & advisorying.

Keywords: (none) => advisory, validated_update
CC: (none) => lewyssmith, sysadmin-bugs

Comment 6 Mageia Robot 2018-12-28 11:17:55 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0492.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.