Input validation error in Wireshark - CVE-2019-19553
Published: December 5, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in CMS dissector. A remote attacker can send a specially crafted traffic or pass a specially crafted file to the application and perform a denial of service (DoS) attack.
Affected software
wireshark (Alpine package)
wireshark
wireshark-debugsource
wireshark-devel
wireshark-debuginfo
wireshark-help
Opensuse
openEuler
How to mitigate CVE-2019-19553
wireshark (Alpine package) - update to 3.0.7-r0
wireshark - update to 2.6.2-18
wireshark-debugsource - update to 2.6.2-18
wireshark-devel - update to 2.6.2-18
wireshark-debuginfo - update to 2.6.2-18
wireshark-help - update to 2.6.2-18