5.3

CVE-2019-15165

sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tcpdump ≫ Libpcap Version < 1.9.1
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Opensuse ≫ Leap Version 15.0
Opensuse ≫ Leap Version 15.1
Apple ≫ iPadOS Version 13.3
Apple ≫ iPhone OS Version 13.3
Apple ≫ macOS X Version >= 10.13 < 10.13.6
Apple ≫ macOS X Version 10.13.6 Update security_update_2019-007
Apple ≫ macOS X Version 10.14.6 Update security_update_2019-002
Apple ≫ macOS X Version 10.15.2
Apple ≫ tvOS Version 13.3
Apple ≫ watchOS Version 6.1.1
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.83% 0.848
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CISA-ADP 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

http://seclists.org/fulldisclosure/2019/Dec/26
Third Party Advisory
Mailing List
Issue Tracking
https://seclists.org/bugtraq/2019/Dec/23
Third Party Advisory
Mailing List
https://support.apple.com/kb/HT210788
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html
Third Party Advisory
https://support.apple.com/kb/HT210785
Third Party Advisory
https://support.apple.com/kb/HT210789
Third Party Advisory
https://support.apple.com/kb/HT210790
Third Party Advisory
https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.9/CHANGES
Product
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5P5K3DQ4TFSZBDB3XN4CZNJNQ3UIF3D3/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GBIEKWLNIR62KZ5GA7EDXZS52HU6OE5F/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UZTIPUWABYUE5KQOLCKAW65AUUSB7QO6/
https://www.tcpdump.org/public-cve-list.txt
Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00051.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00052.html
Third Party Advisory
Mailing List
https://github.com/the-tcpdump-group/libpcap/commit/87d6bef033062f969e70fa40c43dfd945d5a20ab
Patch
Third Party Advisory
https://github.com/the-tcpdump-group/libpcap/commit/a5a36d9e82dde7265e38fe1f87b7f11c461c29f6
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/10/msg00031.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2021/12/msg00014.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4221-1/
Third Party Advisory
https://usn.ubuntu.com/4221-2/
Third Party Advisory