Wireshark 'epan/packet.c' Denial of Service Vulnerability
BID:108464
CVE-2019-12295 |Info
Wireshark 'epan/packet.c' Denial of Service Vulnerability
| Bugtraq ID: | 108464 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2019-12295 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2019 12:00AM |
| Updated: | May 21 2019 12:00AM |
| Credit: | Buildbot Builder |
| Vulnerable: |
Wireshark Wireshark 3.0.1 Wireshark Wireshark 3.0 Wireshark Wireshark 2.6.8 Wireshark Wireshark 2.6.7 Wireshark Wireshark 2.6.6 Wireshark Wireshark 2.6.5 Wireshark Wireshark 2.6.4 Wireshark Wireshark 2.6.3 Wireshark Wireshark 2.6.2 Wireshark Wireshark 2.6.1 Wireshark Wireshark 2.6 Wireshark Wireshark 2.4.14 Wireshark Wireshark 2.4.13 Wireshark Wireshark 2.4.12 Wireshark Wireshark 2.4.11 Wireshark Wireshark 2.4.10 Wireshark Wireshark 2.4.9 Wireshark Wireshark 2.4.8 Wireshark Wireshark 2.4.7 Wireshark Wireshark 2.4.6 Wireshark Wireshark 2.4.5 Wireshark Wireshark 2.4.4 Wireshark Wireshark 2.4.3 Wireshark Wireshark 2.4.1 Wireshark Wireshark 2.4 Wireshark Wireshark 2.4.2 |
| Not Vulnerable: |
Wireshark Wireshark 3.0.2 Wireshark Wireshark 2.6.9 Wireshark Wireshark 2.4.15 |
Discussion
Wireshark 'epan/packet.c' Denial of Service Vulnerability
Wireshark is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Exploit / POC
Wireshark 'epan/packet.c' Denial of Service Vulnerability
Sample packet trace files are available in the Wireshark bug reports. Please see the references for more information.
Sample packet trace files are available in the Wireshark bug reports. Please see the references for more information.
Solution / Fix
Wireshark 'epan/packet.c' Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Wireshark 'epan/packet.c' Denial of Service Vulnerability
References:
References: