PT-2019-5385 · Wireshark+2 · Wireshark+2
Publicado
2019-04-09
·
Atualizado
2024-06-15
·
CVE-2019-10902
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Wireshark version 3.0.0
Description
The issue is related to the TSDNS dissector in Wireshark, which could crash due to errors in resource management. This could potentially allow a remote attacker to cause a denial of service. The problem was addressed by safely splitting strings in the dissector code.
Recommendations
For Wireshark version 3.0.0, update the epan/dissectors/packet-tsdns.c file to include the fix that splits strings safely to prevent crashes.
Exploit
Correção
Unchecked Return Value
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Wireshark