Vulnerability Description
rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.
CVSS Score
5.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tcpdump | Libpcap | < 1.9.1 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2019/Dec/26
- https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.9/CHANGESProductRelease Notes
- https://github.com/the-tcpdump-group/libpcap/commit/33834cb2a4d035b52aa2a26742f8PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://seclists.org/bugtraq/2019/Dec/23
- https://support.apple.com/kb/HT210785
- https://support.apple.com/kb/HT210788
- https://support.apple.com/kb/HT210789
- https://support.apple.com/kb/HT210790
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.tcpdump.org/public-cve-list.txtVendor Advisory
- http://seclists.org/fulldisclosure/2019/Dec/26
- https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.9/CHANGESProductRelease Notes
FAQ
What is CVE-2019-15164?
CVE-2019-15164 is a vulnerability with a CVSS score of 5.3 (MEDIUM). rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.
How severe is CVE-2019-15164?
CVE-2019-15164 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15164?
Check the references section above for vendor advisories and patch information. Affected products include: Tcpdump Libpcap.