Vulnerability Description
rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tcpdump | Libpcap | < 1.9.1 |
| Opengroup | Unix | - |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2019/Dec/26
- https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.9/CHANGESProductRelease Notes
- https://github.com/the-tcpdump-group/libpcap/commit/484d60cbf7ca4ec758c3cbb8a82dPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://seclists.org/bugtraq/2019/Dec/23
- https://support.apple.com/kb/HT210785
- https://support.apple.com/kb/HT210788
- https://support.apple.com/kb/HT210789
- https://support.apple.com/kb/HT210790
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.tcpdump.org/public-cve-list.txtVendor Advisory
- http://seclists.org/fulldisclosure/2019/Dec/26
- https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.9/CHANGESProductRelease Notes
FAQ
What is CVE-2019-15162?
CVE-2019-15162 is a vulnerability with a CVSS score of 5.3 (MEDIUM). rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.
How severe is CVE-2019-15162?
CVE-2019-15162 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15162?
Check the references section above for vendor advisories and patch information. Affected products include: Tcpdump Libpcap, Opengroup Unix.