In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash. This was addressed in epan/dissectors/packet-rpcap.c by avoiding an attempted dereference of a NULL conversation.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wireshark | Mar 20, 2019 | Feb 28, 2019 |
| Debian | — | Upgrade wireshark | Mar 25, 2019 | Feb 27, 2019 |
| Suse | — | Upgrade spandsp-develUpgrade libwsutil8Upgrade libwiretap7Upgrade mmdblookupUpgrade spandsp-docUpgrade libwireshark9Upgrade wireshark-gtkUpgrade libwiretap10Upgrade libspandsp2Upgrade libwsutil11Upgrade wireshark-ui-qtUpgrade libmaxminddb-develUpgrade libmaxminddb0-32bitUpgrade libspandsp2-32bitUpgrade libwscodecs1Upgrade wireshark-develUpgrade libwireshark13Upgrade wiresharkUpgrade libmaxminddb0 | Apr 1, 2019 | Feb 27, 2019 |
| Ubuntu | — | Upgrade wireshark-qtUpgrade libwsutil9Upgrade tsharkUpgrade libwireshark11Upgrade wireshark-gtkUpgrade wiresharkUpgrade wireshark-commonUpgrade libwireshark-dataUpgrade libwiretap8Upgrade libwscodecs2 | May 17, 2019 | Feb 27, 2019 |
| Wireshark | — | Upgrade to Wireshark version 2.4.13Upgrade to Wireshark version 2.6.7 | Mar 4, 2019 | Feb 27, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub