In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/dissectors/packet-dof.c by properly handling generated IID and OID bytes.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wireshark | May 2, 2019 | Apr 9, 2019 |
| Debian | — | Upgrade wireshark | Nov 2, 2020 | Apr 9, 2019 |
| Oracle Solaris | — | Upgrade diagnostic/wireshark to version 2.6.8-11.4.9.0.1.2.0 on Solaris 11.4Upgrade diagnostic/wireshark/tshark to version 2.6.8-11.4.9.0.1.2.0 on Solaris 11.4Upgrade diagnostic/wireshark/wireshark-common to version 2.6.8-11.4.9.0.1.2.0 on Solaris 11.4 | May 30, 2019 | Apr 9, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 9, 2019 |
| Suse | — | Upgrade libwsutil11Upgrade libwsutil8Upgrade libwireshark13Upgrade spandsp-docUpgrade wiresharkUpgrade libwiretap7Upgrade libwiretap10Upgrade mmdblookupUpgrade libwireshark9Upgrade libspandsp2Upgrade libmaxminddb-develUpgrade wireshark-develUpgrade spandsp-develUpgrade libwscodecs1Upgrade libspandsp2-32bitUpgrade libmaxminddb0Upgrade wireshark-gtkUpgrade wireshark-ui-qtUpgrade libmaxminddb0-32bit | Apr 26, 2019 | Apr 9, 2019 |
| Ubuntu | — | Upgrade wireshark-qtUpgrade libwireshark11Upgrade wireshark-gtkUpgrade libwscodecs2Upgrade tsharkUpgrade libwsutil9Upgrade libwireshark-dataUpgrade libwiretap8Upgrade wiresharkUpgrade wireshark-common | May 17, 2019 | Apr 9, 2019 |
| Wireshark | — | Upgrade to Wireshark version 2.4.14Upgrade to Wireshark version 2.6.8Upgrade to Wireshark version 3.0.1 | Apr 15, 2019 | Apr 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub