Bug 1353525 (CVE-2016-6160)

Summary: CVE-2016-6160 tcpreplay: Tcprewrite does not check the size of frames it processes
Product: [Other] Security Response Reporter: Andrej Nemec <anemec>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: bojan
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-07-19 08:16:37 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1353526, 1353527    
Bug Blocks:    

Description Andrej Nemec 2016-07-07 11:38:11 UTC
tcprewrite program, part of the tcpreplay suite, does not check the size of the frames it processes. Huge frames may trigger a segmentation fault, as they occur on interfaces with an MTU of or close to 65536. For example, the loopback interface lo of the Linux kernel has such a value.

References:

http://seclists.org/oss-sec/2016/q3/10

Comment 1 Andrej Nemec 2016-07-07 11:38:39 UTC
Created tcpreplay tracking bugs for this issue:

Affects: fedora-all [bug 1353526]
Affects: epel-all [bug 1353527]

Comment 2 Fedora Update System 2016-07-18 18:24:07 UTC
tcpreplay-4.1.1-2.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.

Comment 3 Fedora Update System 2016-07-18 20:52:24 UTC
tcpreplay-4.1.1-2.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 4 Fedora Update System 2016-07-24 20:18:57 UTC
tcpreplay-4.1.1-2.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2016-07-24 21:48:12 UTC
tcpreplay-4.1.1-2.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2016-07-24 21:49:11 UTC
tcpreplay-4.1.1-2.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.