PT-2019-5385 · Wireshark+2 · Wireshark+2

Published

2019-04-09

·

Updated

2024-06-15

·

CVE-2019-10902

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wireshark version 3.0.0
Description The issue is related to the TSDNS dissector in Wireshark, which could crash due to errors in resource management. This could potentially allow a remote attacker to cause a denial of service. The problem was addressed by safely splitting strings in the dissector code.
Recommendations For Wireshark version 3.0.0, update the epan/dissectors/packet-tsdns.c file to include the fix that splits strings safely to prevent crashes.

Exploit

Fix

Unchecked Return Value

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1633
BDU:2020-02716
CVE-2019-10902
OPENSUSE-SU-2020:0362-1
OPENSUSE-SU-2020_0362-1
OPENSUSE-SU-2024:11513-1
SUSE-SU-2020:0693-1

Affected Products

Alt Linux
Suse
Wireshark