Medium severity5.9OSV Advisory· Published Apr 28, 2019· Updated Jun 17, 2026
CVE-2019-11578
CVE-2019-11578
Description
auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks.
Affected products
3v3.2.3, v5.0.1, v5.0.2, …+ 2 more
- (no CPE)range: v3.2.3, v5.0.1, v5.0.2, …
- cpe:2.3:a:dhcpcd_project:dhcpcd:*:*:*:*:*:*:*:*range: <7.2.1
- (no CPE)range: <7.2.1
Patches
Vulnerability mechanics
References
5- roy.marples.name/git/dhcpcd.git/commit/nvdPatchThird Party Advisory
- roy.marples.name/git/dhcpcd.git/commit/nvdPatchThird Party Advisory
- www.securityfocus.com/bid/108090nvdThird Party AdvisoryVDB Entry
- roy.marples.name/archives/dhcpcd-discuss/0002415.htmlnvdThird Party Advisory
- roy.marples.name/git/dhcpcd.git/commit/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.