Bug ID 1210265
Summary VUL-0: CVE-2023-1801: tcpdump: out-of-bounds write in the SMB printer
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee pmonrealgonzalez@suse.com
Reporter Andreas.Stieger@gmx.de
QA Contact security-team@suse.de
Found By ---
Blocker ---

It was discovered that tcpdump before 4.99.4 contained an out-of-bounds write
in the SMB printer (smbutil.c). The code incorrectly assumed that the format
printed representation of the tm_year variable would always fit into 4
characters, which was not enough. This could lead to stack buffer overflow in
some cases.

References:
https://github.com/the-tcpdump-group/tcpdump/commit/5caf4211264afa7d98820c6cbb6a03c27a388fec
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.99.4/CHANGES#L7


You are receiving this mail because: