CVE-2019-1010220

LOW

tcpdump.org tcpdump <4.9.2 - Buffer Over-read

Title source: llm
STIX 2.1

Description

tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file.

References (11)

Core 11
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4252-2/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4252-1/

Scores

CVSS v3 3.3
EPSS 0.0029
EPSS Percentile 52.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-125 CWE-126
Status published
Products (1)
tcpdump/tcpdump 4.9.2
Published Jul 22, 2019
Tracked Since Feb 18, 2026