Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11961

Опубликовано: 31 дек. 2025
Источник: redhat
CVSS3: 1.9
EPSS Низкий

Описание

pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.

A flaw was found in libpcap. The pcap_ether_aton() function, which processes MAC-48 addresses, does not properly validate input strings. An application that calls this function with a malformed address string can cause the function to read or write data beyond its intended memory boundaries. This can lead to minor data corruption or unexpected application behavior.

Отчет

This vulnerability is rated Low for Red Hat because it requires a specific application to call the pcap_ether_aton() function with a malformed MAC-48 address string. Exploitation is dependent on applications using this auxiliary function with untrusted input, which is not a common scenario in Red Hat products.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libpcapFix deferred
Red Hat Enterprise Linux 6libpcapOut of support scope
Red Hat Enterprise Linux 7libpcapFix deferred
Red Hat Enterprise Linux 8libpcapFix deferred
Red Hat Enterprise Linux 9libpcapFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2426396libpcap: libpcap: Memory corruption via malformed MAC-48 address input

EPSS

Процентиль: 1%
0.00102
Низкий

1.9 Low

CVSS3

Связанные уязвимости

CVSS3: 1.9
ubuntu
8 месяцев назад

pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.

CVSS3: 1.9
nvd
8 месяцев назад

pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.

CVSS3: 1.9
msrc
8 месяцев назад

OOBR and OOBW in pcap_ether_aton() in libpcap

CVSS3: 1.9
debian
8 месяцев назад

pcap_ether_aton() is an auxiliary function in libpcap, it takes a stri ...

suse-cvrf
7 месяцев назад

Security update for libpcap

EPSS

Процентиль: 1%
0.00102
Низкий

1.9 Low

CVSS3