CVE-2019-15166

low-risk
Published 2019-10-03

lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.

Do I need to act?

~
1.0% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
1
CVSS 1.6/10 Low
PHYSICAL / HIGH complexity

References (32)

Third Party Advisory https://usn.ubuntu.com/4252-1/
Third Party Advisory https://usn.ubuntu.com/4252-2/
and 12 more references
26
/ 100
low-risk
Severity 4/34 · Minimal
Exploitability 3/34 · Minimal
Exposure 19/34 · Moderate