← back
CVE-2019-1010220

CVE-2019-1010220

EPSS 1.3%CWE-126
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
22 Jul 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file.
Affected products
tcpdump.org · tcpdump

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →