PT-2019-5385 · Wireshark+2 · Wireshark+2
Published
2019-04-09
·
Updated
2024-06-15
·
CVE-2019-10902
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Wireshark version 3.0.0
Description
The issue is related to the TSDNS dissector in Wireshark, which could crash due to errors in resource management. This could potentially allow a remote attacker to cause a denial of service. The problem was addressed by safely splitting strings in the dissector code.
Recommendations
For Wireshark version 3.0.0, update the epan/dissectors/packet-tsdns.c file to include the fix that splits strings safely to prevent crashes.
Exploit
Fix
Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Suse
Wireshark