PT-2019-5385 · Wireshark+2 · Wireshark+2

Publicado

2019-04-09

·

Atualizado

2024-06-15

·

CVE-2019-10902

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wireshark version 3.0.0
Description The issue is related to the TSDNS dissector in Wireshark, which could crash due to errors in resource management. This could potentially allow a remote attacker to cause a denial of service. The problem was addressed by safely splitting strings in the dissector code.
Recommendations For Wireshark version 3.0.0, update the epan/dissectors/packet-tsdns.c file to include the fix that splits strings safely to prevent crashes.

Exploit

Correção

Unchecked Return Value

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1633
BDU:2020-02716
CVE-2019-10902
OPENSUSE-SU-2020:0362-1
OPENSUSE-SU-2020_0362-1
OPENSUSE-SU-2024:11513-1
SUSE-SU-2020:0693-1

Produtos afetados

Alt Linux
Suse
Wireshark