Candidate: CVE-2019-1010142 PublicDate: 2019-07-19 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010142 https://github.com/secdev/scapy/pull/1409 https://github.com/secdev/scapy/commit/0d7ae2b039f650a40e511d09eb961c782da025d9 (v2.4.1) https://github.com/secdev/scapy/pull/1409/files#diff-441eff981e466959968111fc6314fe93L1058 https://www.imperva.com/blog/scapy-sploit-python-network-tool-is-vulnerable-to-denial-of-service-dos-attack-cve-pending/ Description: scapy 2.4.0 is affected by: Denial of Service. The impact is: infinite loop, resource consumption and program unresponsive. The component is: _RADIUSAttrPacketListField.getfield(self..). The attack vector is: over the network or in a pcap. both work. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_scapy: upstream_scapy: released (2.4.2-1) precise/esm_scapy: DNE trusty_scapy: ignored (out of standard support) trusty/esm_scapy: DNE xenial_scapy: not-affected (code not present) bionic_scapy: not-affected (code not present) disco_scapy: not-affected (code not present) devel_scapy: not-affected (2.4.2-1)