USN-3955-1: tcpflow vulnerabilities
It was discovered that tcpflow incorrectly handled certain malformed network packets. A remote attacker could send these packets to a target system, causing tcpflow to crash or possibly disclose sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-3955-1?
The severity of USN-3955-1 is considered to be high due to the potential for crashes and information disclosure.
How do I fix USN-3955-1?
To fix USN-3955-1, upgrade to the latest version of tcpflow or tcpflow-nox that addresses this vulnerability.
What are the affected versions listed in USN-3955-1?
The affected versions in USN-3955-1 include tcpflow and tcpflow-nox for Ubuntu releases 16.04, 18.04, and 18.10.
Can USN-3955-1 be exploited remotely?
Yes, USN-3955-1 can be exploited remotely by sending malformed network packets to a vulnerable system.
What are the potential impacts of USN-3955-1?
The potential impacts of USN-3955-1 include crashes of the tcpflow service and possible exposure of sensitive information.