CVE-2019-1010220: Medium severity tcpdump tcpdump vulnerability
Last updated 25 August 2025
Other sources
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "NDPRINT((ndo, "%s", buf));", in function named "printprefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-1010220.
What is the impact of the vulnerability?
The impact is the potential exposure of Saved Frame Pointer, Return Address, etc. on the stack.
Which component is affected by the vulnerability?
The component affected is line 234: "ND_PRINT((ndo, "%s", buf));", in the function named "print_prefix", in "print-hncp.c".
What is the attack vector for this vulnerability?
The attack vector requires the victim to open a maliciously crafted packet capture file or be on a network where malicious packets are being captured.
How can I fix the vulnerability?
To fix the vulnerability, update tcpdump to version 4.9.3 or later.