HIGH
scapy 2.4.0 is affected by: Denial of Service
Published Jul 19, 2019
7.5
HIGHCVSS 3.1
EPSS 2.79%
Description
scapy 2.4.0 is affected by: Denial of Service. The impact is: infinite loop, resource consumption and program unresponsive. The component is: _RADIUSAttrPacketListField.getfield(self..). The attack vector is: over the network or in a pcap. both work.
Affected products
-
- Version 2.4.0StatusaffectedConstraints-
- Version
Configuration 2
OR
- 29
- 30
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://www.securityfocus.com/bid/106674 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- https://github.com/advisories/GHSA-mpf2-q34c-fc6j Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/scapy/PYSEC-2019-120.yaml
- https://github.com/secdev/scapy/pull/1409 x_refsource_MISCPatchThird Party Advisory
- https://github.com/secdev/scapy/pull/1409/files#diff-441eff981e466959968111fc6314fe93L1058 x_refsource_MISCPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42NRPMC3NS2QVFNIXYP6WV2T3LMLLY7E/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T46XW4S5BCA3VV3JT3C5Q6LBEXSIACLN/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42NRPMC3NS2QVFNIXYP6WV2T3LMLLY7E
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T46XW4S5BCA3VV3JT3C5Q6LBEXSIACLN
- https://nvd.nist.gov/vuln/detail/CVE-2019-1010142
- https://www.imperva.com/blog/scapy-sploit-python-network-tool-is-vulnerable-to-denial-of-service-dos-attack-cve-pending x_refsource_MISCExploitPatchThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dwf
Published Jul 19, 2019
Updated Aug 5, 2024
Reserved Mar 20, 2019
Link CVE-2019-1010142
CISA Vulnrichment
GHSA-MPF2-Q34C-FC6J Updated n/a