Wireshark CVE-2019-13619 Denial of Service Vulnerability
BID:109293
CVE-2019-13619 |Info
Wireshark CVE-2019-13619 Denial of Service Vulnerability
| Bugtraq ID: | 109293 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2019-13619 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2019 12:00AM |
| Updated: | Jul 17 2019 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Wireshark Wireshark 3.0.2 Wireshark Wireshark 3.0.1 Wireshark Wireshark 3.0 Wireshark Wireshark 2.6.9 Wireshark Wireshark 2.6.8 Wireshark Wireshark 2.6.7 Wireshark Wireshark 2.6.6 Wireshark Wireshark 2.6.5 Wireshark Wireshark 2.6.4 Wireshark Wireshark 2.6.3 Wireshark Wireshark 2.6.2 Wireshark Wireshark 2.6.1 Wireshark Wireshark 2.6 Wireshark Wireshark 2.4.15 Wireshark Wireshark 2.4.14 Wireshark Wireshark 2.4.13 Wireshark Wireshark 2.4.12 Wireshark Wireshark 2.4.11 Wireshark Wireshark 2.4.10 Wireshark Wireshark 2.4.9 Wireshark Wireshark 2.4.8 Wireshark Wireshark 2.4.7 Wireshark Wireshark 2.4.6 Wireshark Wireshark 2.4.5 Wireshark Wireshark 2.4.4 Wireshark Wireshark 2.4.3 Wireshark Wireshark 2.4.1 Wireshark Wireshark 2.4 Wireshark Wireshark 2.4.2 |
| Not Vulnerable: |
Wireshark Wireshark 3.0.3 Wireshark Wireshark 2.6.10 Wireshark Wireshark 2.4.16 |
Discussion
Wireshark CVE-2019-13619 Denial of Service Vulnerability
Wireshark is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark version 3.0.0 through 3.0.2, 2.6.0 through 2.6.9, 2.4.0 through 2.4.15 are vulnerable.
Wireshark is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark version 3.0.0 through 3.0.2, 2.6.0 through 2.6.9, 2.4.0 through 2.4.15 are vulnerable.
References
Wireshark CVE-2019-13619 Denial of Service Vulnerability
References:
References:
- asn1: don't increment a buffer beyond its end. 36/33736/2 (Wireshark)
- Wireshark Homepage (Wireshark)
- Bug 15870 - [oss-fuzz] #15221 Heap-buffer-overflow in asn1_get_real (Wireshark)
- Bug 1731022 (CVE-2019-13619) - CVE-2019-13619 wireshark: AN.1 BER dissector cra (Redhat)
- CVE-2019-13619 (Redhat)
- wnpa-sec-2019-20 · ASN.1 BER and related dissectors crash (Wireshark)