Vulnerability Description
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tcpdump | Tcpdump | < 4.9.3 |
Related Weaknesses (CWE)
References
- https://github.com/the-tcpdump-group/tcpdump/commit/a152aebfd1114376ba266ed30416PatchThird Party Advisory
- https://github.com/the-tcpdump-group/tcpdump/commit/a152aebfd1114376ba266ed30416PatchThird Party Advisory
FAQ
What is CVE-2019-15167?
CVE-2019-15167 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.
How severe is CVE-2019-15167?
CVE-2019-15167 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-15167?
Check the references section above for vendor advisories and patch information. Affected products include: Tcpdump Tcpdump.