Resource management error in Wireshark - CVE-2019-12295
Published: September 10, 2019
Vulnerability identifier: #VU20968
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12295
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to unspecified error when processing untrusted data in the Wireshark dissection engine in epan/packet.c. A remote attacker can trick the victim to view the malformed packet trace file and crash the application.Affected software
Wireshark
wireshark (Ubuntu package)
wireshark (Alpine package)
wireshark
wireshark-devel
wireshark-help
wireshark-debugsource
wireshark-debuginfo
BIG-IP
openEuler
wireshark (Ubuntu package)
wireshark (Alpine package)
wireshark
wireshark-devel
wireshark-help
wireshark-debugsource
wireshark-debuginfo
BIG-IP
openEuler
How to mitigate CVE-2019-12295
Install updates from vendor's website.
Wireshark - addressed in versions 2.4.15, 2.6.9, 3.0.2
wireshark (Ubuntu package) - addressed in versions 2.6.10-1~ubuntu16.04.0, 2.6.10-1~ubuntu18.04.0, 2.6.10-1~ubuntu19.04.0
wireshark (Alpine package) - update to 2.6.9-r0
wireshark - update to 2.6.2-20
wireshark-devel - update to 2.6.2-20
wireshark-help - update to 2.6.2-20
wireshark-debugsource - update to 2.6.2-20
wireshark-debuginfo - update to 2.6.2-20
wireshark (Ubuntu package) - addressed in versions 2.6.10-1~ubuntu16.04.0, 2.6.10-1~ubuntu18.04.0, 2.6.10-1~ubuntu19.04.0
wireshark (Alpine package) - update to 2.6.9-r0
wireshark - update to 2.6.2-20
wireshark-devel - update to 2.6.2-20
wireshark-help - update to 2.6.2-20
wireshark-debugsource - update to 2.6.2-20
wireshark-debuginfo - update to 2.6.2-20