Re: [tcpdump-workers] CVE-2020-8037: memory allocation in ppp decapsulator

2020-11-30 Thread Bill Fenner via tcpdump-workers
--- Begin Message --- On Mon, Nov 30, 2020 at 12:59 PM Michael Richardson wrote: > Hi, CVE-2020-8037 causes a big amount of memory to be allocated (then > freed), > it does not cause an attack. That's helpful information. (On a low-memory device that actually requires memory at malloc time, it

Re: [tcpdump-workers] CVE-2020-8037: memory allocation in ppp decapsulator

2020-11-30 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Hi, CVE-2020-8037 causes a big amount of memory to be allocated (then freed), it does not cause an attack. I'm sorry that I haven't managed to succeed in doing the right CVE.json dance to get the mitre data updated. Bill Fenner via tcpdump-workers wrote: > I realize tha

[tcpdump-workers] CVE-2020-8037: memory allocation in ppp decapsulator

2020-11-30 Thread Bill Fenner via tcpdump-workers
--- Begin Message --- I see that Red Hat/Fedora have released new packages to address CVE-2020-8037 in tcpdump. Does the tcpdump group have any message about this CVE? Is there a release from tcpdump.org with this CVE fixed? See https://bugzilla.redhat.com/show_bug.cgi?id=1895080 for details (po