Buffer overflow in libpcap - CVE-2019-15165
Published: October 21, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the sf-pcapng.c in libpcap when processing the PHB header length before allocating memory. A remote attacker can pass specially crafted data to the application that uses the vulnerable library, trigger memory corruption and perform denial of service (DoS) attack.
Affected software
libpcap (Ubuntu package)
libpcap (Alpine package)
libpcap
libpcap (Red Hat package)
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Tivoli Storage Manager
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Oracle Solaris
Opensuse
Fedora
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
How to mitigate CVE-2019-15165
libpcap (Ubuntu package) - addressed in versions 1.7.4-2ubuntu0.1, 1.8.1-6ubuntu1.18.04.1, 1.8.1-6ubuntu1.19.04.1
libpcap (Alpine package) - update to 1.9.1-r0
Quay - update to 3.3.3
libpcap - addressed in versions 1.9.1-1.fc29, 1.9.1-1.fc30, 1.9.1-1.fc31
libpcap (Red Hat package) - update to 1.9.1-4.el8
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
External References
Related Security Bulletins
- OpenSUSE Linux update for libpcap
- OpenSUSE Linux update for libpcap
- Multiple vulnerabilities in libpcap
- Ubuntu update for libpcap
- Oracle Solaris update for third party packages
- Buffer overflow in libpcap (Alpine package)
- Red Hat Enterprise Linux 8 update for libpcap
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Fedora 30 update for libpcap
- Fedora 31 update for libpcap
- Fedora 29 update for libpcap
- Dell EMC Unity update for third-party components