Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Oct 28, 2006 |
| Suse | — | Upgrade libwireshark18Upgrade libwireshark19Upgrade libwiretap16Upgrade libwsutil16Upgrade libwsutil17Upgrade wiresharkUpgrade wireshark-ui-qtUpgrade wireshark-develUpgrade libwiretap15 | Feb 17, 2015 | Jun 28, 2013 |
| Wireshark | — | Upgrade to Wireshark version 0.99.4 | Oct 4, 2017 | Oct 27, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub