CVE-2025-11961
Last modified
CVE-2025-11961 is a low-severity vulnerability rated 1.9/10 on the CVSS scale. pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-11961?
How severe is CVE-2025-11961?
How do I fix CVE-2025-11961?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-11956Improper Neutralization of Input During Web Page Generation …8.9
- CVE-2025-11957Improper authorization in the temporary access workflow of D…9
- CVE-2025-11958An improper input validation in the Security Dashboard ignor…5.1
- CVE-2025-11959Files or Directories Accessible to External Parties, Exposur…8.1
- CVE-2025-1196A vulnerability, which was classified as problematic, was fo…5.4
- CVE-2025-11960Improper Neutralization of Input During Web Page Generation …6.1
- CVE-2025-11962Improper Neutralization of Input During Web Page Generation …7.3
- CVE-2025-11963Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2025-11964On Windows only, if libpcap needs to convert a Windows error…1.9
- CVE-2025-11965In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4…7.5
- CVE-2025-11966In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4…6.4
- CVE-2025-11967The Mail Mint plugin for WordPress is vulnerable to arbitrar…7.2
Are you affected by CVE-2025-11961?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
