Hi Romain,

On Sat, Apr 08, 2023 at 09:49:05PM +0200, Romain Francoise wrote:
> Hi Salvatore,
> 
> On Sat, Apr 8, 2023 at 1:51 PM Salvatore Bonaccorso <car...@debian.org> wrote:
> > The following vulnerability was published for tcpdump.
> >
> > CVE-2023-1801[0]:
> > | The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-
> > | of-bounds write when decoding a crafted network packet.
> 
> Thanks. Just in case, I will mention that the SMB printer code is
> *not* enabled in Debian anymore. None of the supported distributions
> (oldstable, stable, testing/sid) are affected.

Ah right, I see the binary packages are not affected by the respective
code path, so have marked this in the security-tracker accordingly as
unimportant.

Thanks,

Regards,
Salvatore

Reply via email to