nfdump 1.6.17 and earlier is affected by an integer overflow in the function Processipfixtemplate_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service).
[
{
"id": "CVE-2019-14459-28d0cf76",
"source": "https://github.com/phaag/nfdump/commit/3b006ededaf351f1723aea6c727c9edd1b1fff9b",
"signature_version": "v1",
"digest": {
"length": 445.0,
"function_hash": "2566065934500313209064802284287609098"
},
"deprecated": false,
"signature_type": "Function",
"target": {
"function": "Process_ipfix_template_withdraw",
"file": "bin/ipfix.c"
}
},
{
"id": "CVE-2019-14459-9ed48c63",
"source": "https://github.com/phaag/nfdump/commit/3b006ededaf351f1723aea6c727c9edd1b1fff9b",
"signature_version": "v1",
"digest": {
"length": 4554.0,
"function_hash": "255931474877025429624093994592633441352"
},
"deprecated": false,
"signature_type": "Function",
"target": {
"function": "Process_ipfix_template_add",
"file": "bin/ipfix.c"
}
},
{
"id": "CVE-2019-14459-d0710105",
"source": "https://github.com/phaag/nfdump/commit/3b006ededaf351f1723aea6c727c9edd1b1fff9b",
"signature_version": "v1",
"digest": {
"line_hashes": [
"61093887762454218481233648391296405957",
"59834892523595629546671054081810919351",
"278423574008120186746432230498105753055",
"234917007496416288369355897334790062791",
"119039669925299467230396952435174491989",
"194799690917280427686831918636223352098",
"169117545355776012287811733532588520142"
],
"threshold": 0.9
},
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "bin/ipfix.c"
}
}
]