The X.509if dissector in Wireshark 1.2.x before 1.2.16 and 1.4.x before 1.4.5 does not properly initialize certain global variables, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade wireshark-develUpgrade wiresharkUpgrade wireshark-gnome | Dec 1, 2016 | Apr 29, 2011 |
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Apr 29, 2011 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Apr 29, 2011 |
| Oracle_linux | — | Upgrade wiresharkUpgrade wireshark-gnomeUpgrade wireshark-devel | Oct 16, 2024 | Apr 29, 2011 |
| Suse | — | Upgrade libwsutil8Upgrade libwireshark9Upgrade libwsutil7Upgrade libwsutil17Upgrade wireshark-gtkUpgrade libwiretap7Upgrade libwsutil16Upgrade wireshark-ui-qtUpgrade libwireshark19Upgrade wiresharkUpgrade libwiretap16Upgrade libwiretap15Upgrade libwireshark18Upgrade wireshark-develUpgrade libwscodecs1Upgrade libwiretap6Upgrade libwireshark8 | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Apr 29, 2011 |
| Wireshark | — | Upgrade to Wireshark version 1.2.16Upgrade to Wireshark version 1.4.5 | May 3, 2018 | Apr 29, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub