The dissect_protocol_data_parameter function in epan/dissectors/packet-m3ua.c in the M3UA dissector in Wireshark 1.10.x before 1.10.6 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a crafted SS7 MTP3 packet.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Mar 11, 2014 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Mar 11, 2014 |
| Oracle Solaris | — | Upgrade diagnostic/wireshark/wireshark-common to version 1.8.13-0.175.1.19.0.1.0 on Solaris 11.1Upgrade diagnostic/wireshark/tshark to version 1.8.13-0.175.1.19.0.1.0 on Solaris 11.1Upgrade diagnostic/wireshark to version 1.8.13-0.175.1.19.0.1.0 on Solaris 11.1 | May 29, 2017 | Mar 11, 2014 |
| Suse | — | Upgrade wireshark-gtkUpgrade wireshark-develUpgrade wireshark-ui-qtUpgrade libwscodecs1Upgrade wiresharkUpgrade libwsutil8Upgrade libwiretap7Upgrade libwsutil7Upgrade libwireshark8Upgrade libwiretap6Upgrade libwireshark9 | Dec 18, 2015 | Mar 11, 2014 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Mar 11, 2014 |
| Wireshark | — | Upgrade to Wireshark version 1.10.6 | Oct 4, 2017 | Mar 11, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub