The iseries_check_file_type function in wiretap/iseries.c in the iSeries file parser in Wireshark 2.0.x before 2.0.2 does not consider that a line may lack the "OBJECT PROTOCOL" substring, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Feb 28, 2016 |
| Freebsd | — | Upgrade wiresharkUpgrade wireshark-liteUpgrade tshark-liteUpgrade tsharkUpgrade wireshark-qt5 | Dec 10, 2025 | Mar 1, 2016 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Feb 27, 2016 |
| Suse | — | Upgrade libwscodecs1Upgrade wiresharkUpgrade wireshark-develUpgrade wireshark-ui-qtUpgrade libwsutil11Upgrade libwiretap10Upgrade libwiretap7Upgrade libwsutil8Upgrade libwireshark9Upgrade libwireshark13 | Dec 9, 2016 | Feb 27, 2016 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Feb 28, 2016 |
| Wireshark | — | Upgrade to Wireshark version 2.0.2 | Apr 25, 2018 | Feb 27, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub