Echo: libpcap: security update to 1.10.5-2+e1

low Tenable Self-Hosted Container Security Plugin ID 463003

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size
allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported
formats, but this requirement has been poorly documented. If an application calls the function with an
argument that deviates from the expected format, the function can read data beyond the end of the provided
string and write data beyond the end of the allocated buffer. (CVE-2025-11961)

Solution

Update the libpcap library and its related packages to version 1.10.5-2+e1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-11961

Plugin Details

Severity: Low

ID: 463003

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.54

CVSS v2

Risk Factor: Low

Base Score: 0.8

Temporal Score: 0.6

Vector: CVSS2#AV:L/AC:H/Au:M/C:N/I:P/A:N

CVSS Score Source: CVE-2025-11961

CVSS v3

Risk Factor: Low

Base Score: 1.9

Temporal Score: 1.7

Vector: CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/3/2026

Vulnerability Publication Date: 12/31/2025

Reference Information

CVE: CVE-2025-11961

IAVA: 2026-A-0013-S