Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed file.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade wiresharkUpgrade wireshark-gnome | Dec 1, 2016 | Feb 8, 2011 |
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Feb 8, 2011 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Feb 8, 2011 |
| Oracle_linux | — | Upgrade wireshark-gnomeUpgrade wiresharkUpgrade wireshark-devel | Oct 16, 2024 | Feb 8, 2011 |
| Suse | — | Upgrade libwireshark18Upgrade libwireshark8Upgrade libwsutil16Upgrade libwiretap7Upgrade libwiretap16Upgrade libwsutil7Upgrade wireshark-develUpgrade libwiretap6Upgrade libwireshark9Upgrade libwireshark19Upgrade wireshark-gtkUpgrade libwscodecs1Upgrade libwsutil8Upgrade libwsutil17Upgrade libwiretap15Upgrade wireshark-ui-qtUpgrade wireshark | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Feb 8, 2011 |
| Wireshark | — | Upgrade to Wireshark version 1.2.15Upgrade to Wireshark version 1.4.4 | Oct 4, 2017 | Feb 8, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub