CVE-2011-1935
9.8
CRITICAL
CVSS 3.1
EPSS 1.3%
Description
pcap-linux.c in libpcap 1.1.1 before commit ea9432fabdf4b33cbc76d9437200e028f1c47c93 when snaplen is set may truncate packets, which might allow remote attackers to send arbitrary data while avoiding detection via crafted packets.
How to fix CVE-2011-1935
To remediate CVE-2011-1935, upgrade the affected package to a fixed version below.
- Debian/libpcap—upgrade to 1.1.1-4 or later
Is CVE-2011-1935 being exploited?
Low — EPSS is 1.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.1.1-4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |