CVE-2019-15162: Medium severity tvos vulnerability
libpcap. Multiple issues were addressed by updating to libpcap version 1.9.1
Other sources
rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.
Credit
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-15162.
What is the severity level of CVE-2019-15162?
The severity level of CVE-2019-15162 is medium, with a severity value of 5.3.
What is the affected software?
The affected software includes Tcpdump Libpcap version up to 1.9.1, Apple watchOS version up to 6.1.1, Apple tvOS version up to 13.3, Apple iOS version up to 13.3, and Apple iPadOS version up to 13.3.
What is the description of CVE-2019-15162?
CVE-2019-15162 is a vulnerability in libpcap before version 1.9.1 on non-Windows platforms, which may provide details about why authentication failed, making it easier for attackers to enumerate valid usernames.
How can I mitigate the vulnerability?
To mitigate the vulnerability, update the affected software to the recommended versions: libpcap version 1.9.1 for Tcpdump Libpcap, watchOS version 6.1.1 or later, tvOS version 13.3 or later, iOS version 13.3 or later, and iPadOS version 13.3 or later.