5.9
CVSSv3

CVE-2019-11578

Published: 28/04/2019 Updated: 21/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

auth.c in dhcpcd prior to 7.2.1 allowed malicious users to infer secrets by performing latency attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dhcpcd project dhcpcd

Vendor Advisories

Debian Bug report logs - #928056 dhcpcd5: CVE-2019-11578: auth: Use consttime_memequal to avoid latency attack Package: src:dhcpcd5; Maintainer for src:dhcpcd5 is Scott Leggett <scott@slidau>; Reported by: "Timo Sigurdsson" <public_timos@silentcreekde> Date: Sat, 27 Apr 2019 01:57:01 UTC Severity: serious Tags: f ...
Debian Bug report logs - #928440 dhcpcd5: CVE-2019-11766: DHCPv6: Potential read overflow with D6_OPTION_PD_EXCLUDE Package: dhcpcd5; Maintainer for dhcpcd5 is Scott Leggett <scott@slidau>; Source for dhcpcd5 is src:dhcpcd5 (PTS, buildd, popcon) Reported by: "Timo Sigurdsson" <public_timos@silentcreekde> Date: Sa ...
Debian Bug report logs - #928104 dhcpcd5: CVE-2019-11579: DHCP: Fix a potential 1 byte read overflow with DHO_OPTSOVERLOADED Package: src:dhcpcd5; Maintainer for src:dhcpcd5 is Scott Leggett <scott@slidau>; Reported by: "Timo Sigurdsson" <public_timos@silentcreekde> Date: Sat, 27 Apr 2019 01:57:01 UTC Severity: s ...
Debian Bug report logs - #928105 dhcpcd5: CVE-2019-11577: DHCPv6: Fix a potential buffer overflow reading NA/TA addresses Package: src:dhcpcd5; Maintainer for src:dhcpcd5 is Scott Leggett <scott@slidau>; Reported by: "Timo Sigurdsson" <public_timos@silentcreekde> Date: Sat, 27 Apr 2019 01:57:01 UTC Severity: seri ...