Vulnerability Description
In tcpdump 4.9.2, a stack-based buffer over-read exists in the print_prefix function of print-hncp.c via crafted packet data because of missing initialization.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tcpdump | Tcpdump | 4.9.2 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/106098Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:3976
- https://github.com/zyingp/temp/blob/master/tcpdump.mdExploitMitigationThird Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://usn.ubuntu.com/4252-1/
- https://usn.ubuntu.com/4252-2/
- http://www.securityfocus.com/bid/106098Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:3976
- https://github.com/zyingp/temp/blob/master/tcpdump.mdExploitMitigationThird Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44516
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2018-19519?
CVE-2018-19519 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In tcpdump 4.9.2, a stack-based buffer over-read exists in the print_prefix function of print-hncp.c via crafted packet data because of missing initialization.
How severe is CVE-2018-19519?
CVE-2018-19519 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19519?
Check the references section above for vendor advisories and patch information. Affected products include: Tcpdump Tcpdump.