The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000 dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' and '\r' characters, which allows remote attackers to cause a denial of service (off-by-one buffer underflow and application crash) via a crafted packet.
CVSS Details
- CVSS 3.1 Base Score: 6.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Aug 1, 2014 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Aug 1, 2014 |
| Oracle Solaris | — | Upgrade diagnostic/wireshark/wireshark-common to version 1.10.9-0.175.2.2.0.3.0 on Solaris 11.2Upgrade diagnostic/wireshark to version 1.10.9-0.175.2.2.0.3.0 on Solaris 11.2Upgrade diagnostic/wireshark/tshark to version 1.10.9-0.175.2.2.0.3.0 on Solaris 11.2 | May 29, 2017 | Aug 1, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 31, 2014 |
| Suse | — | Upgrade wireshark-gtkUpgrade wiresharkUpgrade libwscodecs1Upgrade wireshark-develUpgrade wireshark-ui-qtUpgrade libwsutil8Upgrade libwiretap7Upgrade libwireshark9Upgrade libwireshark8Upgrade libwsutil7Upgrade libwiretap6 | Dec 18, 2015 | Aug 1, 2014 |
| Wireshark | — | Upgrade to Wireshark version 1.10.9 | Oct 4, 2017 | Aug 1, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub