In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/dissectors/packet-dof.c by properly handling generated IID and OID bytes.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wireshark | May 2, 2019 | Apr 9, 2019 |
| Debian | — | Upgrade wireshark | Nov 2, 2020 | Apr 9, 2019 |
| Oracle Solaris | — | Upgrade diagnostic/wireshark/tshark to version 2.6.8-11.4.9.0.1.2.0 on Solaris 11.4Upgrade diagnostic/wireshark/wireshark-common to version 2.6.8-11.4.9.0.1.2.0 on Solaris 11.4Upgrade diagnostic/wireshark to version 2.6.8-11.4.9.0.1.2.0 on Solaris 11.4 | May 30, 2019 | Apr 9, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 9, 2019 |
| Suse | — | Upgrade libwiretap7Upgrade libwireshark13Upgrade spandsp-develUpgrade libwiretap10Upgrade spandsp-docUpgrade wiresharkUpgrade libwireshark9Upgrade mmdblookupUpgrade libwsutil8Upgrade libwsutil11Upgrade libspandsp2Upgrade wireshark-develUpgrade libmaxminddb-develUpgrade libmaxminddb0Upgrade libwscodecs1Upgrade libmaxminddb0-32bitUpgrade wireshark-ui-qtUpgrade wireshark-gtkUpgrade libspandsp2-32bit | Apr 26, 2019 | Apr 9, 2019 |
| Ubuntu | — | Upgrade libwireshark11Upgrade wireshark-gtkUpgrade wireshark-qtUpgrade libwscodecs2Upgrade libwiretap8Upgrade wiresharkUpgrade libwsutil9Upgrade wireshark-commonUpgrade libwireshark-dataUpgrade tshark | May 17, 2019 | Apr 9, 2019 |
| Wireshark | — | Upgrade to Wireshark version 2.6.8Upgrade to Wireshark version 2.4.14Upgrade to Wireshark version 3.0.1 | Apr 15, 2019 | Apr 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub