#VU21950 Buffer overflow in libpcap - CVE-2019-15165

 

#VU21950 Buffer overflow in libpcap - CVE-2019-15165

Published: October 21, 2019


Vulnerability identifier: #VU21950
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-15165
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
libpcap
Software vendor:
Tcpdump.org

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the sf-pcapng.c in libpcap when processing the PHB header length before allocating memory. A remote attacker can pass specially crafted data to the application that uses the vulnerable library, trigger memory corruption and perform denial of service (DoS) attack.


Remediation

Install updates from vendor's website.

External links