CVE-2019-15165
published 2019-10-03CVE-2019-15165: sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
2.83%
85.0th percentile
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_13.3_and_ipados | — | — |
| apple | ipados | — | — |
| apple | iphone_os | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.13 < 10.13.6 | 10.13.6 |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | watchos | — | — |
| apple | watchos | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libpcap | < libpcap 1.9.1-1 (bookworm) | libpcap 1.9.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | communications_operations_monitor | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libpcap vulnerability
vendor_ubuntu·2020-01-15
CVE-2019-15165 libpcap vulnerability
Title: libpcap vulnerability
Summary: Applications using libpcap could be made to crash if given specially
crafted data.
USN-4221-1 fixed a vulnerability in libpcap. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that libpcap did not properly validate PHB headers in
some situations. An attacker could use this to cause a denial of service
(memory exhaustion).
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libpcap vulnerability
vendor_ubuntu·2019-12-11
CVE-2019-15165 libpcap vulnerability
Title: libpcap vulnerability
Summary: Applications using libpcap could be made to crash if given specially
crafted data.
It was discovered that libpcap did not properly validate PHB headers in
some situations. An attacker could use this to cause a denial of service
(memory exhaustion).
Instructions: In general, a standard system update will make all the necessary changes.
Apple
CVE-2019-15165: tvOS 13.3
vendor_apple·2019-12-10·CVSS 5.3
CVE-2019-15165 [MEDIUM] CVE-2019-15165: tvOS 13.3
Apple Security Update: About the security content of tvOS 13.3
Product: tvOS
Version: 13.3
CVE: CVE-2019-15165
Component: CVE-2019-15165
Apple
CVE-2019-15165: iOS 13.3 and iPadOS 13.3
vendor_apple·2019-12-10·CVSS 5.3
CVE-2019-15165 [MEDIUM] CVE-2019-15165: iOS 13.3 and iPadOS 13.3
Apple Security Update: About the security content of iOS 13.3 and iPadOS 13.3
Product: iOS 13.3 and iPadOS
Version: 13.3
CVE: CVE-2019-15165
Component: CVE-2019-15165
Apple
CVE-2019-15165: watchOS 6.1.1
vendor_apple·2019-12-10·CVSS 5.3
CVE-2019-15165 [MEDIUM] CVE-2019-15165: watchOS 6.1.1
Apple Security Update: About the security content of watchOS 6.1.1
Product: watchOS
Version: 6.1.1
CVE: CVE-2019-15165
Component: CVE-2019-15165
Red Hat
libpcap: Resource exhaustion during PHB header length validation
vendor_redhat·2019-09-20·CVSS 5.3
CVE-2019-15165 [MEDIUM] CWE-400 libpcap: Resource exhaustion during PHB header length validation
libpcap: Resource exhaustion during PHB header length validation
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
Statement: A Low Impact has been given to this flaw even though the CVSSv3 is 7.5, because libpcap library is mainly used as part of debugging tools like wireshark or tcpdump, where an impact to the Availability is not considered security relevant in a reasonable scenario.
Package: libpcap (Red Hat Enterprise Linux 6) - Out of support scope
Package: libpcap (Red Hat Enterprise Linux 7) - Fix deferred
Debian
CVE-2019-15165: libpcap - sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header le...
vendor_debian·2019·CVSS 5.3
CVE-2019-15165 [MEDIUM] CVE-2019-15165: libpcap - sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header le...
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
Scope: local
bookworm: resolved (fixed in 1.9.1-1)
bullseye: resolved (fixed in 1.9.1-1)
forky: resolved (fixed in 1.9.1-1)
sid: resolved (fixed in 1.9.1-1)
trixie: resolved (fixed in 1.9.1-1)
GHSA
GHSA-4jh3-696v-qm6r: sf-pcapng
ghsa_unreviewed·2022-05-24
CVE-2019-15165 [MEDIUM] CWE-770 GHSA-4jh3-696v-qm6r: sf-pcapng
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
OSV
CVE-2019-15165: sf-pcapng
osv·2019-10-03·CVSS 5.3
CVE-2019-15165 [MEDIUM] CVE-2019-15165: sf-pcapng
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-15165 libpcap: Resource exhaustion during PHB header length validation
bugzilla·2019-10-10·CVSS 5.3
CVE-2019-15165 [MEDIUM] CVE-2019-15165 libpcap: Resource exhaustion during PHB header length validation
CVE-2019-15165 libpcap: Resource exhaustion during PHB header length validation
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
Upstream patch:
https://github.com/the-tcpdump-group/libpcap/commit/87d6bef033062f969e70fa40c43dfd945d5a20ab
https://github.com/the-tcpdump-group/libpcap/commit/a5a36d9e82dde7265e38fe1f87b7f11c461c29f6
References:
https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.9/CHANGES
Discussion:
Created libpcap tracking bugs for this issue:
Affects: fedora-all [bug 1760624]
---
Statement:
A Low Impact has been given to this flaw even though the CVSSv3 is 7.5, because libpcap library is mainly used as part of debugging tools like wireshark or tcpdump, where an impact to the Availability is not
Bugzilla
CVE-2018-16301 CVE-2019-15161 CVE-2019-15162 CVE-2019-15163 CVE-2019-15164 CVE-2019-15165 libpcap: various flaws [fedora-all]
bugzilla·2019-10-10·CVSS 7.8
CVE-2018-16301 [HIGH] CVE-2018-16301 CVE-2019-15161 CVE-2019-15162 CVE-2019-15163 CVE-2019-15164 CVE-2019-15165 libpcap: various flaws [fedora-all]
CVE-2018-16301 CVE-2019-15161 CVE-2019-15162 CVE-2019-15163 CVE-2019-15164 CVE-2019-15165 libpcap: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
arXiv
Match & Mend: Minimally Invasive Local Reassembly for Patching N-day Vulnerabilities in ARM Binaries
arxiv_fulltext·2025-10-16
Match & Mend: Minimally Invasive Local Reassembly for Patching N-day Vulnerabilities in ARM Binaries
expansion=sloppyMatch\,&\,Mend: Minimally Invasive Local Reassembly for Patching N-day Vulnerabilities in ARM Binaries
Sebastian Jänich
LMU Munich, Germany
[email protected]
Merlin Sievers
LMU Munich, Germany
[email protected]
Johannes Kinder
LMU Munich, Germany
[email protected]
* [1] #1
[1]
[colback=yellow!30, colframe=yellow!30, boxrule=0mm, arc=0mm, boxsep=0.5mm]#1
definitionDefinition
## Abstract
Low-cost Internet of Things (IoT) devices are increasingly popular but often insecure due to poor update regimes. As a result, many devices run outdated and known-vulnerable versions of open-source software.
We address this problem by proposing to patch IoT firmware at the binary level, without requiring vendor support. In particular, we introduce minimally invas
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00051.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00052.htmlhttp://seclists.org/fulldisclosure/2019/Dec/26https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.9/CHANGEShttps://github.com/the-tcpdump-group/libpcap/commit/87d6bef033062f969e70fa40c43dfd945d5a20abhttps://github.com/the-tcpdump-group/libpcap/commit/a5a36d9e82dde7265e38fe1f87b7f11c461c29f6https://lists.debian.org/debian-lts-announce/2019/10/msg00031.htmlhttps://lists.debian.org/debian-lts-announce/2021/12/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5P5K3DQ4TFSZBDB3XN4CZNJNQ3UIF3D3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GBIEKWLNIR62KZ5GA7EDXZS52HU6OE5F/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UZTIPUWABYUE5KQOLCKAW65AUUSB7QO6/https://seclists.org/bugtraq/2019/Dec/23https://support.apple.com/kb/HT210785https://support.apple.com/kb/HT210788https://support.apple.com/kb/HT210789https://support.apple.com/kb/HT210790https://usn.ubuntu.com/4221-1/https://usn.ubuntu.com/4221-2/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.tcpdump.org/public-cve-list.txthttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00051.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00052.htmlhttp://seclists.org/fulldisclosure/2019/Dec/26https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.9/CHANGEShttps://github.com/the-tcpdump-group/libpcap/commit/87d6bef033062f969e70fa40c43dfd945d5a20abhttps://github.com/the-tcpdump-group/libpcap/commit/a5a36d9e82dde7265e38fe1f87b7f11c461c29f6https://lists.debian.org/debian-lts-announce/2019/10/msg00031.htmlhttps://lists.debian.org/debian-lts-announce/2021/12/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5P5K3DQ4TFSZBDB3XN4CZNJNQ3UIF3D3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GBIEKWLNIR62KZ5GA7EDXZS52HU6OE5F/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UZTIPUWABYUE5KQOLCKAW65AUUSB7QO6/https://seclists.org/bugtraq/2019/Dec/23https://support.apple.com/kb/HT210785https://support.apple.com/kb/HT210788https://support.apple.com/kb/HT210789https://support.apple.com/kb/HT210790https://usn.ubuntu.com/4221-1/https://usn.ubuntu.com/4221-2/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.tcpdump.org/public-cve-list.txt
2019-10-03
Published