Input validation error in Wireshark - CVE-2019-13619
Published: July 23, 2019
Vulnerability identifier: #VU19319
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13619
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the ASN.1 BER dissector in epan/asn1.c. A remote attacker can send malicious traffic to the affected application and perform a denial of service attack.
Affected software
Wireshark
wireshark (Ubuntu package)
wireshark (Alpine package)
wireshark
wireshark-debugsource
wireshark-devel
wireshark-debuginfo
wireshark-help
Opensuse
openEuler
Fedora
wireshark (Ubuntu package)
wireshark (Alpine package)
wireshark
wireshark-debugsource
wireshark-devel
wireshark-debuginfo
wireshark-help
Opensuse
openEuler
Fedora
How to mitigate CVE-2019-13619
Install updates from vendor's website.
Wireshark - addressed in versions 2.4.16, 2.6.10, 3.0.3
wireshark (Ubuntu package) - addressed in versions 2.6.10-1~ubuntu16.04.0, 2.6.10-1~ubuntu18.04.0, 2.6.10-1~ubuntu19.04.0
wireshark (Alpine package) - update to 3.0.3-r0
wireshark - update to 2.6.2-18
wireshark-debugsource - update to 2.6.2-18
wireshark-devel - update to 2.6.2-18
wireshark-debuginfo - update to 2.6.2-18
wireshark-help - update to 2.6.2-18
wireshark - addressed in versions 3.0.3-1.fc29, 3.0.3-1.fc30
wireshark (Ubuntu package) - addressed in versions 2.6.10-1~ubuntu16.04.0, 2.6.10-1~ubuntu18.04.0, 2.6.10-1~ubuntu19.04.0
wireshark (Alpine package) - update to 3.0.3-r0
wireshark - update to 2.6.2-18
wireshark-debugsource - update to 2.6.2-18
wireshark-devel - update to 2.6.2-18
wireshark-debuginfo - update to 2.6.2-18
wireshark-help - update to 2.6.2-18
wireshark - addressed in versions 3.0.3-1.fc29, 3.0.3-1.fc30