Red Hat Bugzilla – Bug 1475355
CVE-2017-11542 tcpdump: heap-based buffer over-read in the pimv1_print
Last modified: 2018-05-15 22:43:43 EDT
tcpdump 4.9.0 has a heap-based buffer over-read in the pimv1_print function in print-pim.c. Reproducer: https://github.com/hackerlib/hackerlib-vul/tree/master/tcpdump-vul/heap-buffer-overflow/print-pim
Created tcpdump tracking bugs for this issue: Affects: fedora-all [bug 1475364]
This issue was addressed in Red Hat Enterprise Linux 7 via RHEA-2018:0705, which rebased tcpdump to 4.9.2: https://access.redhat.com/errata/RHEA-2018:0705