First published: Fri Oct 20 2017(Updated: )
pcap-linux.c in libpcap 1.1.1 before commit ea9432fabdf4b33cbc76d9437200e028f1c47c93 when snaplen is set may truncate packets, which might allow remote attackers to send arbitrary data while avoiding detection via crafted packets.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libpcap | 1.10.0-2 1.10.3-1 1.10.4-5 | |
Libpcap | >=1.1.1<1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1935 is considered a medium severity vulnerability due to potential unauthorized data exposure.
To fix CVE-2011-1935, upgrade to libpcap versions 1.10.0-2, 1.10.3-1, or 1.10.4-5.
CVE-2011-1935 is caused by the truncation of packets when the snaplen parameter is set, allowing crafted packets to bypass detection.
Users running affected versions of libpcap, particularly versions from 1.1.1 to 1.2.1, are vulnerable to CVE-2011-1935.
Attackers can exploit CVE-2011-1935 to send arbitrary data undetected, potentially leading to further exploitation.