First published: Wed Apr 24 2019(Updated: )
It was discovered that tcpflow incorrectly handled certain malformed network packets. A remote attacker could send these packets to a target system, causing tcpflow to crash or possibly disclose sensitive information.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/tcpflow | <1.4.5+repack1-4ubuntu0.18.10.1 | 1.4.5+repack1-4ubuntu0.18.10.1 |
Ubuntu Linux | =18.10 | |
All of | ||
ubuntu/tcpflow-nox | <1.4.5+repack1-4ubuntu0.18.10.1 | 1.4.5+repack1-4ubuntu0.18.10.1 |
Ubuntu Linux | =18.10 | |
All of | ||
ubuntu/tcpflow | <1.4.5+repack1-4ubuntu0.18.04.1 | 1.4.5+repack1-4ubuntu0.18.04.1 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/tcpflow-nox | <1.4.5+repack1-4ubuntu0.18.04.1 | 1.4.5+repack1-4ubuntu0.18.04.1 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/tcpflow | <1.4.5+repack1-1ubuntu0.1 | 1.4.5+repack1-1ubuntu0.1 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/tcpflow-nox | <1.4.5+repack1-1ubuntu0.1 | 1.4.5+repack1-1ubuntu0.1 |
Ubuntu Linux | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-3955-1 is considered to be high due to the potential for crashes and information disclosure.
To fix USN-3955-1, upgrade to the latest version of tcpflow or tcpflow-nox that addresses this vulnerability.
The affected versions in USN-3955-1 include tcpflow and tcpflow-nox for Ubuntu releases 16.04, 18.04, and 18.10.
Yes, USN-3955-1 can be exploited remotely by sending malformed network packets to a vulnerable system.
The potential impacts of USN-3955-1 include crashes of the tcpflow service and possible exposure of sensitive information.