Skip to main content

Incorrect Calculation of Buffer Size

CVE-2019-15161

Severity Medium
Score 5.3/10

Summary

The "rpcapd/daemon.c" file in libpcap versions prior to 1.9.1 mishandles certain length values because of reuse of a variable. This may open up an attack vector involving extra data at the end of a request.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-131 - Incorrect Calculation of Buffer Size

The software does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

Advisory Timeline

  • Published