CVE-2019-11578: Medium severity dhcpcd vulnerability
Published Apr 28, 2019
·Updated
auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks.
Affected Software
1 affected component
Dhcpcd Project Dhcpcd<7.2.1
Remediation
Event History
Apr 28, 2019
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-11578?
CVE-2019-11578 has a medium severity level due to its potential to allow information leakage through latency attacks.
2
How do I fix CVE-2019-11578?
To fix CVE-2019-11578, upgrade to dhcpcd version 7.2.1 or later.
3
What systems are affected by CVE-2019-11578?
CVE-2019-11578 affects all versions of dhcpcd prior to 7.2.1.
4
What types of attacks does CVE-2019-11578 enable?
CVE-2019-11578 enables attackers to perform latency attacks to infer secrets.
5
Who reports vulnerabilities like CVE-2019-11578?
Vulnerabilities like CVE-2019-11578 are typically reported by security researchers and organizations focusing on software security.