tcpdump multiple CVEs
Bug #1662177 reported by
Gianfranco Costamagna
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
tcpdump (Ubuntu) |
Fix Released
|
Medium
|
Gianfranco Costamagna |
Bug Description
disclaimer for the version bump: Debian did the same, so I presume their security team had good reasons to do it
[14:39:59] <LocutusOfBorg> reverse-depends... tcpdump is a tool, not a library
[14:40:17] <LocutusOfBorg> I reverse-depends can use it by calling the binary, and the commandline didn't change
[14:40:23] <LocutusOfBorg> so, I presume everything is fine
[14:40:38] <LocutusOfBorg> wrt apparmor, you are right
[14:41:52] <LocutusOfBorg> btw I'm using tcpdump on xenial right now, it works as usual
CVE References
- 2014-8767
- 2014-8768
- 2014-8769
- 2014-9140
- 2015-0261
- 2015-2153
- 2015-2154
- 2015-2155
- 2016-7922
- 2016-7923
- 2016-7924
- 2016-7925
- 2016-7926
- 2016-7927
- 2016-7928
- 2016-7929
- 2016-7930
- 2016-7931
- 2016-7932
- 2016-7933
- 2016-7934
- 2016-7935
- 2016-7936
- 2016-7937
- 2016-7938
- 2016-7939
- 2016-7940
- 2016-7973
- 2016-7974
- 2016-7975
- 2016-7983
- 2016-7984
- 2016-7985
- 2016-7986
- 2016-7992
- 2016-7993
- 2016-8574
- 2016-8575
- 2017-5202
- 2017-5203
- 2017-5204
- 2017-5205
- 2017-5341
- 2017-5342
- 2017-5482
- 2017-5483
- 2017-5484
- 2017-5485
- 2017-5486
information type: | Public → Public Security |
Changed in tcpdump (Ubuntu): | |
importance: | Undecided → Medium |
tags: | added: patch |
tags: | added: trusty xenial yakkety |
Changed in tcpdump (Ubuntu): | |
status: | Incomplete → New |
To post a comment you must log in.
Thanks for the debdiffs! I'll need a little more info before I seriously begin sponsoring them. Note that since tcpdump is in main, I'll still need to do my own QA.
What investigation did you perform to feel comfortable in disabling the tests that were disabled?
What amount of testing did you perform? In which Ubuntu releases and in what environment (whether or not in a VM, the CPU architecture, etc.)?