PT-2019-1725 · Wireshark+3 · Wireshark+3

Dario Lombardo

·

Publicado

2018-04-03

·

Atualizado

2024-06-15

·

CVE-2019-9214

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wireshark versions 2.4.0 through 2.4.12 Wireshark versions 2.6.0 through 2.6.6
Description The issue is related to the RPCAP dissector in Wireshark, which could crash due to a NULL conversation dereference. This could potentially allow a remote attacker to cause a denial of service using a specially crafted packet or packet capture file.
Recommendations For Wireshark versions 2.4.0 through 2.4.12, update to a version where the issue is fixed by avoiding the attempted dereference of a NULL conversation in epan/dissectors/packet-rpcap.c. For Wireshark versions 2.6.0 through 2.6.6, update to a version where the issue is fixed by avoiding the attempted dereference of a NULL conversation in epan/dissectors/packet-rpcap.c. As a temporary workaround, consider disabling the RPCAP dissector until a patch is available.

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1549
ALT-PU-2019-1411
BDU:2019-01351
CVE-2019-9214
DSA-4416-1
OPENSUSE-SU-2019:1108-1
OPENSUSE-SU-2019_1108-1
OPENSUSE-SU-2019_1390-1
OPENSUSE-SU-2020:0362-1
OPENSUSE-SU-2020_0362-1
OPENSUSE-SU-2024:11513-1
SUSE-SU-2019:0619-1
SUSE-SU-2019:0688-1
SUSE-SU-2020:0693-1
USN-3986-1

Produtos afetados

Alt Linux
Suse
Ubuntu
Wireshark