Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade wiresharkUpgrade wireshark-gnome | Dec 1, 2016 | Nov 26, 2010 |
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Nov 26, 2010 |
| Freebsd | — | Upgrade tshark-liteUpgrade wiresharkUpgrade wireshark-liteUpgrade tshark | Dec 10, 2025 | Nov 5, 2010 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Nov 26, 2010 |
| Oracle_linux | — | Upgrade wireshark-gnomeUpgrade wiresharkUpgrade wireshark-devel | Oct 16, 2024 | Nov 26, 2010 |
| Redhat_linux | — | — | Jul 9, 2025 | Sep 13, 2010 |
| Suse | — | Upgrade libwsutil17Upgrade libwiretap15Upgrade libwsutil7Upgrade libwiretap6Upgrade libwsutil16Upgrade wireshark-gtkUpgrade wireshark-ui-qtUpgrade libwscodecs1Upgrade wireshark-develUpgrade libwiretap7Upgrade libwireshark8Upgrade libwsutil8Upgrade libwireshark9Upgrade libwireshark18Upgrade libwiretap16Upgrade wiresharkUpgrade libwireshark19 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Nov 26, 2010 |
| Wireshark | — | Upgrade to Wireshark version 1.4.1Upgrade to Wireshark version 1.2.12 | Oct 4, 2017 | Nov 26, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub