CVE-2019-12295Uncontrolled Recursion in Wireshark

Severity
7.5HIGHNVD
EPSS
1.4%
top 19.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateMay 24

Description

In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages15 packages

Debianwireshark/wireshark< 2.6.8-1.1+3
NVDwireshark/wireshark2.4.02.4.14+2
NVDf5/big-ip_analytics12.1.3.612.1.5.3+5
NVDf5/big-ip_edge_gateway12.1.3.612.1.5.3+5
NVDf5/big-ip_webaccelerator12.1.3.612.1.5.3+5

Also affects: Debian Linux 9.0, Ubuntu Linux 16.04, 18.04, 19.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6c7j-gh7x-rw3h: In Wireshark 32022-05-24
OSV
CVE-2019-12295: In Wireshark 32019-05-23
CVEList
CVE-2019-12295: In Wireshark 32019-05-23

📋Vendor Advisories

3
Ubuntu
Wireshark vulnerabilities2019-09-16
Red Hat
wireshark: missing dissection recursion checks leads to denial of service2019-05-21
Debian
CVE-2019-12295: wireshark - In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection...2019

💬Community

2
Bugzilla
CVE-2019-12295 wireshark: missing dissection recursion checks leads to denial of service2020-05-05
Bugzilla
CVE-2019-12295 wireshark: missing dissection recursion checks leads to denial of service [fedora-all]2020-05-05
CVE-2019-12295 — Uncontrolled Recursion in Wireshark | cvebase