Wireshark Multiple Denial of Service Vulnerabilities
BID:107836
CVE-2019-10897 | CVE-2019-10898 | CVE-2019-10900 | CVE-2019-10902 |Info
Wireshark Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 107836 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2019-10897 CVE-2019-10898 CVE-2019-10900 CVE-2019-10902 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2019 12:00AM |
| Updated: | Apr 09 2019 12:00AM |
| Credit: | Buildbot Builder, Dario Lombardo, and Mateusz Jurczyk. |
| Vulnerable: |
Wireshark Wireshark 3.0 |
| Not Vulnerable: |
Wireshark Wireshark 3.0.1 |
Discussion
Wireshark Multiple Denial of Service Vulnerabilities
Wireshark is prone to multiple denial-of-service vulnerabilities.
An attacker can exploit these issues by injecting a malformed packet onto the wire or by convincing someone to read a malformed 'pcap' file.
Attackers can exploit these issues to crash the affected application, denying service to legitimate users.
Wireshark 3.0.0 is vulnerable; other versions may also be vulnerable.
Wireshark is prone to multiple denial-of-service vulnerabilities.
An attacker can exploit these issues by injecting a malformed packet onto the wire or by convincing someone to read a malformed 'pcap' file.
Attackers can exploit these issues to crash the affected application, denying service to legitimate users.
Wireshark 3.0.0 is vulnerable; other versions may also be vulnerable.
Exploit / POC
Wireshark Multiple Denial of Service Vulnerabilities
Sample packet trace files are available in the Wireshark bug reports. Please see the references for more information.
Sample packet trace files are available in the Wireshark bug reports. Please see the references for more information.
Solution / Fix
Wireshark Multiple Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Wireshark Multiple Denial of Service Vulnerabilities
References:
References:
- Bug 15553 - Buildbot crash output: fuzz-2019-03-04-11320.pcap (Wireshark)
- Bug 15619 - Wireshark SIGSEGV due to use of uninitialized memory (Wireshark)
- Wireshark Homepage (Wireshark)
- Bug 15585 - [oss-fuzz] #13232: Timeout in wireshark_fuzzshark_ip (Wireshark)
- Bug 15612 - Wireshark unhandled exception (Wireshark)
- wnpa-sec-2019-11 · IEEE 802.11 dissector infinite loop (Wireshark)
- wnpa-sec-2019-12 · GSUP dissector infinite loop (Wireshark)
- wnpa-sec-2019-13 · Rbm dissector infinite loop (Wireshark)
- wnpa-sec-2019-16 · TSDNS dissector crash (Wireshark)