CVE-2019-15166

LOW

Tcpdump < 4.9.3 - Buffer Overflow

Title source: rule

Description

lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.

Exploits (1)

nomisec WRITEUP
by Satheesh575555 · poc
https://github.com/Satheesh575555/external_tcpdump_AOSP10_r33_CVE-2019-15166

References (16)

Scores

CVSS v3 1.6
EPSS 0.0102
EPSS Percentile 76.9%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

Classification

CWE
CWE-120
Status published

Affected Products (19)

tcpdump/tcpdump < 4.9.3
apple/mac_os_x < 10.15.2
debian/debian_linux
debian/debian_linux
debian/debian_linux
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
opensuse/leap
opensuse/leap
redhat/enterprise_linux
redhat/enterprise_linux
netapp/cloud_backup
netapp/hci_management_node
netapp/solidfire
... and 4 more

Timeline

Published Oct 03, 2019
Tracked Since Feb 18, 2026