CVE-2019-15163: Null Pointer Dereference
libpcap. Multiple issues were addressed by updating to libpcap version 1.9.1
Other sources
rpcapd/daemon.c in libpcap before 1.9.1 allows attackers to cause a denial of service (NULL pointer dereference and daemon crash) if a crypt() call fails.
Credit
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-15163.
What is the severity level of CVE-2019-15163?
The severity level of CVE-2019-15163 is high.
What is the description of CVE-2019-15163?
CVE-2019-15163 is a vulnerability in libpcap that allows attackers to cause a denial of service by triggering a NULL pointer dereference and daemon crash when a crypt() call fails.
Which software versions are affected by CVE-2019-15163?
Tcpdump Libpcap versions up to 1.9.1, Apple watchOS up to 6.1.1, Apple tvOS up to 13.3, Apple iOS up to 13.3, and Apple iPadOS up to 13.3 are affected by CVE-2019-15163.
How can I fix CVE-2019-15163?
To fix CVE-2019-15163, update to libpcap version 1.9.1 or apply the necessary security patches provided by Apple for watchOS, tvOS, iOS, and iPadOS.