CVE-2019-15165

Name
CVE-2019-15165
Description
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Product https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.9/CHANGES
Patch https://github.com/the-tcpdump-group/libpcap/commit/a5a36d9e82dde7265e38fe1f87b7f11c461c29f6
Vendor Advisory https://www.tcpdump.org/public-cve-list.txt
Patch https://github.com/the-tcpdump-group/libpcap/commit/87d6bef033062f969e70fa40c43dfd945d5a20ab
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00052.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00051.html
MLIST https://lists.debian.org/debian-lts-announce/2019/10/msg00031.html
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UZTIPUWABYUE5KQOLCKAW65AUUSB7QO6/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5P5K3DQ4TFSZBDB3XN4CZNJNQ3UIF3D3/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GBIEKWLNIR62KZ5GA7EDXZS52HU6OE5F/
CONFIRM https://support.apple.com/kb/HT210788
UBUNTU https://usn.ubuntu.com/4221-1/
BUGTRAQ https://seclists.org/bugtraq/2019/Dec/23
FULLDISC http://seclists.org/fulldisclosure/2019/Dec/26
UBUNTU https://usn.ubuntu.com/4221-2/
CONFIRM https://support.apple.com/kb/HT210790
CONFIRM https://support.apple.com/kb/HT210785
CONFIRM https://support.apple.com/kb/HT210789
N/A https://www.oracle.com/security-alerts/cpuapr2020.html
Mailing List https://lists.debian.org/debian-lts-announce/2021/12/msg00014.html
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5P5K3DQ4TFSZBDB3XN4CZNJNQ3UIF3D3/
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GBIEKWLNIR62KZ5GA7EDXZS52HU6OE5F/
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UZTIPUWABYUE5KQOLCKAW65AUUSB7QO6/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:tcpdump:libpcap:*:*:*:*:*:*:*:* libpcap >= None < 1.9.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libpcap edge-main 1.9.1-r0 None fixed
libpcap 3.22-main 1.9.1-r0 None fixed
libpcap 3.21-main 1.9.1-r0 None fixed
libpcap 3.20-main 1.9.1-r0 None fixed
libpcap 3.19-main 1.9.1-r0 None fixed
libpcap 3.18-main 1.9.1-r0 None fixed
libpcap 3.17-main 1.9.1-r0 None fixed
libpcap 3.12-main 1.9.1-r0 None fixed
libpcap 3.10-main 1.1.1-r0 None fixed