Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame.
| Software | From | Fixed in |
|---|---|---|
| opensuse / opensuse | 13.1 | 13.1.x |
| opensuse / opensuse | 13.2 | 13.2.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| canonical / ubuntu_linux | 14.10 | 14.10.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| canonical / ubuntu_linux | 10.04 | 10.04.x |
| oracle / solaris | 11.2 | 11.2.x |
| redhat / tcpdump | 4.5.0 | 4.5.0.x |
| redhat / tcpdump | 4.5.1 | 4.5.1.x |
| redhat / tcpdump | 4.5.2 | 4.5.2.x |
| redhat / tcpdump | 4.6.0 | 4.6.0.x |
| redhat / tcpdump | 4.6.1 | 4.6.1.x |
| redhat / tcpdump | 4.6.2 | 4.6.2.x |