5.3

CVE-2019-15165

sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.

Data is provided by the National Vulnerability Database (NVD)
TcpdumpLibpcap Version < 1.9.1
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
OpensuseLeap Version15.0
OpensuseLeap Version15.1
AppleiPadOS Version13.3
AppleiPhone OS Version13.3
ApplemacOS X Version >= 10.13 < 10.13.6
ApplemacOS X Version10.13.6 Updatesecurity_update_2019-007
ApplemacOS X Version10.14.6 Updatesecurity_update_2019-002
ApplemacOS X Version10.15.2
AppletvOS Version13.3
ApplewatchOS Version6.1.1
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version16.04 SwEditionesm
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version19.04
FedoraprojectFedora Version29
FedoraprojectFedora Version30
FedoraprojectFedora Version31
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.19% 0.782
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.

http://seclists.org/fulldisclosure/2019/Dec/26
Third Party Advisory
Mailing List
Issue Tracking
https://seclists.org/bugtraq/2019/Dec/23
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4221-1/
Third Party Advisory
https://usn.ubuntu.com/4221-2/
Third Party Advisory