CVE-2018-14463: High severity macos catalina vulnerability
Last updated 24 July 2024
Other sources
tcpdump. Multiple issues were addressed by updating to tcpdump version 4.9.3 and libpcap version 1.9.1
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrpprint() for VRRP version 2, a different vulnerability than CVE-2019-15167.
— Launchpad
Credit
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8837
- CVE-2019-8853
- CVE-2019-8856
- CVE-2019-8848
- CVE-2019-8834
- CVE-2019-8842
- CVE-2019-8839
- CVE-2019-8830
- CVE-2019-8851
- CVE-2019-8833
- CVE-2019-8828
- CVE-2019-8838
- CVE-2019-8847
- CVE-2019-8852
- CVE-2019-15903
- CVE-2020-9782
- CVE-2012-1164
- CVE-2012-2668
- CVE-2013-4449
- CVE-2015-1545
- CVE-2019-13057
- CVE-2019-13565
- CVE-2019-8832
- CVE-2017-16808
- CVE-2018-10103
- CVE-2018-10105
- CVE-2018-14461
- CVE-2018-14462
- CVE-2018-14463
- CVE-2018-14464
- CVE-2018-14465
- CVE-2018-14466
- CVE-2018-14467
- CVE-2018-14468
- CVE-2018-14469
- CVE-2018-14470
- CVE-2018-14879
- CVE-2018-14880
- CVE-2018-14881
- CVE-2018-14882
- CVE-2018-16227
- CVE-2018-16228
- CVE-2018-16229
- CVE-2018-16230
- CVE-2018-16300
- CVE-2018-16301
- CVE-2018-16451
- CVE-2018-16452
- CVE-2019-15166
- CVE-2019-15167
- CVE-2019-15126
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-14463.
What is the severity of CVE-2018-14463?
The severity of CVE-2018-14463 is high (7.5).
Which software versions are affected by CVE-2018-14463?
macOS Catalina 10.15.2, Apple Mojave, Apple High Sierra, tcpdump 4.9.3-1~deb10u2, tcpdump 4.9.3-1~deb10u1, tcpdump 4.99.0-2+deb11u1, tcpdump 4.99.3-1, tcpdump 4.99.4-3, tcpdump 4.9.3-0ubuntu0.18.04.1, tcpdump 4.9.3-0ubuntu0.14.04.1+, tcpdump 4.9.3, tcpdump 4.9.3-0ubuntu0.16.04.1, and Tcpdump 4.9.3 are affected by CVE-2018-14463.
How can I fix CVE-2018-14463 in macOS Catalina?
Update macOS Catalina to version 10.15.2 or later.
How can I fix CVE-2018-14463 in tcpdump?
Update tcpdump to version 4.9.3 or later.