Candidate: CVE-2019-14459 PublicDate: 2019-07-31 21:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14459 https://github.com/phaag/nfdump/commit/3b006ededaf351f1723aea6c727c9edd1b1fff9b https://github.com/phaag/nfdump/issues/171 Description: nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service). Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_nfdump: upstream_nfdump: needs-triage precise/esm_nfdump: DNE trusty_nfdump: ignored (out of standard support) trusty/esm_nfdump: DNE xenial_nfdump: not-affected (code not present) bionic_nfdump: needed disco_nfdump: ignored (reached end-of-life) eoan_nfdump: not-affected (1.6.18-1) focal_nfdump: not-affected (1.6.18-1) groovy_nfdump: not-affected (1.6.18-1) hirsute_nfdump: not-affected (1.6.18-1) impish_nfdump: not-affected (1.6.18-1) jammy_nfdump: not-affected (1.6.18-1) devel_nfdump: not-affected (1.6.18-1)