In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/dissectors/packet-dof.c by properly handling generated IID and OID bytes.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wireshark | May 2, 2019 | Apr 9, 2019 |
| Debian | — | Upgrade wireshark | Nov 2, 2020 | Apr 9, 2019 |
| Oracle Solaris | — | Upgrade diagnostic/wireshark/wireshark-common to version 2.6.8-11.4.9.0.1.2.0 on Solaris 11.4Upgrade diagnostic/wireshark/tshark to version 2.6.8-11.4.9.0.1.2.0 on Solaris 11.4Upgrade diagnostic/wireshark to version 2.6.8-11.4.9.0.1.2.0 on Solaris 11.4 | May 30, 2019 | Apr 9, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 9, 2019 |
| Suse | — | Upgrade libmaxminddb0Upgrade libwscodecs1Upgrade wireshark-ui-qtUpgrade wireshark-gtkUpgrade libmaxminddb0-32bitUpgrade libspandsp2-32bitUpgrade libspandsp2Upgrade wiresharkUpgrade libwsutil8Upgrade libwireshark13Upgrade mmdblookupUpgrade libmaxminddb-develUpgrade wireshark-develUpgrade spandsp-develUpgrade libwsutil11Upgrade libwireshark9Upgrade libwiretap7Upgrade libwiretap10Upgrade spandsp-doc | Apr 26, 2019 | Apr 9, 2019 |
| Ubuntu | — | Upgrade libwireshark11Upgrade wireshark-qtUpgrade libwscodecs2Upgrade wireshark-gtkUpgrade libwiretap8Upgrade wiresharkUpgrade wireshark-commonUpgrade tsharkUpgrade libwireshark-dataUpgrade libwsutil9 | May 17, 2019 | Apr 9, 2019 |
| Wireshark | — | Upgrade to Wireshark version 2.4.14Upgrade to Wireshark version 2.6.8Upgrade to Wireshark version 3.0.1 | Apr 15, 2019 | Apr 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub