nfdump 1.6.17 and earlier is affected by an integer overflow in the function Processipfixtemplate_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service).
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.6.18-1", "binary_name": "nfdump" }, { "binary_version": "1.6.18-1", "binary_name": "nfdump-dbgsym" }, { "binary_version": "1.6.18-1", "binary_name": "nfdump-flow-tools" }, { "binary_version": "1.6.18-1", "binary_name": "nfdump-flow-tools-dbgsym" }, { "binary_version": "1.6.18-1", "binary_name": "nfdump-sflow" }, { "binary_version": "1.6.18-1", "binary_name": "nfdump-sflow-dbgsym" } ] }