In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash. This was addressed in epan/dissectors/packet-rpcap.c by avoiding an attempted dereference of a NULL conversation.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wireshark | Mar 20, 2019 | Feb 28, 2019 |
| Debian | — | Upgrade wireshark | Mar 25, 2019 | Feb 27, 2019 |
| Suse | — | Upgrade libwscodecs1Upgrade libmaxminddb0Upgrade wireshark-ui-qtUpgrade libwireshark13Upgrade wireshark-develUpgrade wiresharkUpgrade libmaxminddb-develUpgrade libmaxminddb0-32bitUpgrade libspandsp2-32bitUpgrade mmdblookupUpgrade wireshark-gtkUpgrade libwiretap7Upgrade libwireshark9Upgrade libwsutil8Upgrade spandsp-develUpgrade libwsutil11Upgrade spandsp-docUpgrade libspandsp2Upgrade libwiretap10 | Apr 1, 2019 | Feb 27, 2019 |
| Ubuntu | — | Upgrade wireshark-commonUpgrade libwscodecs2Upgrade libwireshark-dataUpgrade libwiretap8Upgrade wiresharkUpgrade wireshark-gtkUpgrade libwireshark11Upgrade tsharkUpgrade libwsutil9Upgrade wireshark-qt | May 17, 2019 | Feb 27, 2019 |
| Wireshark | — | Upgrade to Wireshark version 2.4.13Upgrade to Wireshark version 2.6.7 | Mar 4, 2019 | Feb 27, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub