Wireshark Multiple Denial of Service Vulnerabilities
BID:107834
CVE-2019-10894 | CVE-2019-10895 | CVE-2019-10896 | CVE-2019-10899 | CVE-2019-10901 | CVE-2019-10903 |Info
Wireshark Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 107834 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2019-10894 CVE-2019-10895 CVE-2019-10896 CVE-2019-10899 CVE-2019-10901 CVE-2019-10903 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2019 12:00AM |
| Updated: | Apr 09 2019 12:00AM |
| Credit: | Dario Lombardo, and Mateusz Jurczyk. |
| Vulnerable: |
Wireshark Wireshark 3.0 Wireshark Wireshark 2.6.7 Wireshark Wireshark 2.6.6 Wireshark Wireshark 2.6.5 Wireshark Wireshark 2.6.4 Wireshark Wireshark 2.6.3 Wireshark Wireshark 2.6.2 Wireshark Wireshark 2.6.1 Wireshark Wireshark 2.6 Wireshark Wireshark 2.4.13 Wireshark Wireshark 2.4.12 Wireshark Wireshark 2.4.11 Wireshark Wireshark 2.4.10 Wireshark Wireshark 2.4.9 Wireshark Wireshark 2.4.8 Wireshark Wireshark 2.4.7 Wireshark Wireshark 2.4.6 Wireshark Wireshark 2.4.5 Wireshark Wireshark 2.4.4 Wireshark Wireshark 2.4.3 Wireshark Wireshark 2.4.1 Wireshark Wireshark 2.4 Wireshark Wireshark 2.4.2 |
| Not Vulnerable: |
Wireshark Wireshark 3.0.1 Wireshark Wireshark 2.6.8 Wireshark Wireshark 2.4.14 |
Discussion
Wireshark Multiple Denial of Service Vulnerabilities
Wireshark is prone to multiple denial-of-service vulnerabilities.
An attacker can exploit these issues by injecting a malformed packet onto the wire or by convincing someone to read a malformed 'pcap' file.
Attackers can exploit these issues to crash the affected application, denying service to legitimate users.
Wireshark 2.4.0 through 2.4.13, 2.6.0 through 2.6.7, and 3.0.0 are vulnerable.
Wireshark is prone to multiple denial-of-service vulnerabilities.
An attacker can exploit these issues by injecting a malformed packet onto the wire or by convincing someone to read a malformed 'pcap' file.
Attackers can exploit these issues to crash the affected application, denying service to legitimate users.
Wireshark 2.4.0 through 2.4.13, 2.6.0 through 2.6.7, and 3.0.0 are vulnerable.
Exploit / POC
Wireshark Multiple Denial of Service Vulnerabilities
Sample packet trace files are available in the Wireshark bug reports. Please see the references for more information.
Sample packet trace files are available in the Wireshark bug reports. Please see the references for more information.
Solution / Fix
Wireshark Multiple Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Wireshark Multiple Denial of Service Vulnerabilities
References:
References:
- Bug 15497 - Multiple out-of-bounds reads in NetScaler trace handling (Wireshark)
- Bug 15546 - [oss-fuzz] #12745 wireshark/fuzzshark_ip_proto-udp (Wireshark)
- Bug 15568 - Wireshark heap out-of-bounds read in print_hex_data_buffer (SPOOLSS) (Wireshark)
- Bug 15617 - [oss-fuzz] #13791 wireshark/fuzzshark_ip_proto-udp (Wireshark)
- Bug 15620 - Wireshark NULL pointer dereference in value_get (Wireshark)
- Wireshark Homepage (Wireshark)
- Bug 15613 - Wireshark assertion failure ("call_dissector_only: assertion failed: (Wireshark)
- wnpa-sec-2019-09 · NetScaler file parser crash (Wireshark)
- wnpa-sec-2019-10 · SRVLOC dissector crash (Wireshark)
- wnpa-sec-2019-14 · GSS-API dissector crash (Wireshark)
- wnpa-sec-2019-15 · DOF dissector crash (Wireshark)
- wnpa-sec-2019-17 · LDSS dissector crash (Wireshark)
- wnpa-sec-2019-18 · DCERPC SPOOLSS dissector crash (Wireshark)