KLA11464
Multiple vulnerabilities in Wireshark

Updated: 06/03/2020
Detect date
?
04/08/2019
Severity
?
Critical
Description

Multiple vulnerabilities were found in Wireshark. Malicious users can exploit these vulnerabilities to cause denial of service.

Below is a complete list of vulnerabilities:

  1. Denial of service vulnerability in SRVLOC dissector can be exploited remotely via specially designed packet.
  2. Denial of service vulnerability in LDSS dissector can be exploited remotely via specially designed packet.
  3. Denial of service vulnerability in GSS-API dissector can be exploited remotely via specially designed packet.
  4. Denial of service vulnerability in DOF dissector can be exploited remotely via specially designed packet.
  5. Denial of service vulnerability in NetScaler file parser can be exploited remotely via specially designed packet.
  6. Denial of service vulnerability in DCERPC SPOOLSS dissector can be exploited remotely via specially designed packet.
Affected products

Wireshark 3.0.x up to 3.0.1
Wireshark 2.6.x up to 2.6.7
Wireshark 2.4.x up to 2.4.13

Solution

Update to the latest version
Get WIreshark

Original advisories

wnpa-sec-2019-10
wnpa-sec-2019-14
wnpa-sec-2019-17
wnpa-sec-2019-15
wnpa-sec-2019-09
wnpa-sec-2019-18

Impacts
?
DoS 
[?]
Related products
Wireshark
CVE-IDS
?
CVE-2019-108995.0Critical
CVE-2019-109015.0Critical
CVE-2019-108945.0Critical
CVE-2019-108965.0Critical
CVE-2019-108955.0Critical
CVE-2019-109035.0Critical
Find out the statistics of the vulnerabilities spreading in your region