CVE-2019-5716
published 2019-01-08CVE-2019-5716: In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its…
PriorityP417medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.42%
70.2th percentile
In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wireshark | < wireshark 2.6.6-1 (bookworm) | wireshark 2.6.6-1 (bookworm) |
| wireshark | wireshark | >= 0 < 2.6.6-1 | 2.6.6-1 |
| wireshark | wireshark | >= 0 < 2.6.6-1 | 2.6.6-1 |
| wireshark | wireshark | >= 0 < 2.6.6-1 | 2.6.6-1 |
| wireshark | wireshark | >= 0 < 2.6.6-1 | 2.6.6-1 |
| wireshark | wireshark | 2.6.0 – 2.6.5 | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4jgf-699w-j7rm: In Wireshark 2
ghsa_unreviewed·2022-05-13
CVE-2019-5716 [MEDIUM] CWE-20 GHSA-4jgf-699w-j7rm: In Wireshark 2
In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.
OSV
CVE-2019-5716: In Wireshark 2
osv·2019-01-08·CVSS 5.5
CVE-2019-5716 [MEDIUM] CVE-2019-5716: In Wireshark 2
In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.
Red Hat
wireshark: reachable assertion in fast_ensure_contiguous() from 6LoWPAN dissector
vendor_redhat·2019-01-08·CVSS 5.5
CVE-2019-5716 [MEDIUM] CWE-617 wireshark: reachable assertion in fast_ensure_contiguous() from 6LoWPAN dissector
wireshark: reachable assertion in fast_ensure_contiguous() from 6LoWPAN dissector
In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.
Package: wireshark (Red Hat Enterprise Linux 5) - Not affected
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Package: wireshark (Red Hat Enterprise Linux 7) - Not affected
Package: wireshark (Red Hat Enterprise Linux 8) - Fix deferred
Debian
CVE-2019-5716: wireshark - In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was address...
vendor_debian·2019·CVSS 5.5
CVE-2019-5716 [MEDIUM] CVE-2019-5716: wireshark - In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was address...
In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.
Scope: local
bookworm: resolved (fixed in 2.6.6-1)
bullseye: resolved (fixed in 2.6.6-1)
forky: resolved (fixed in 2.6.6-1)
sid: resolved (fixed in 2.6.6-1)
trixie: resolved (fixed in 2.6.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-5716 wireshark: 6LoWPAN dissector crash in epan/dissectors/packet-6lowpan.c [fedora-all]
bugzilla·2019-01-18·CVSS 5.5
CVE-2019-5716 [MEDIUM] CVE-2019-5716 wireshark: 6LoWPAN dissector crash in epan/dissectors/packet-6lowpan.c [fedora-all]
CVE-2019-5716 wireshark: 6LoWPAN dissector crash in epan/dissectors/packet-6lowpan.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2019-5716 wireshark: reachable assertion in fast_ensure_contiguous() from 6LoWPAN dissector
bugzilla·2019-01-18·CVSS 5.5
CVE-2019-5716 [MEDIUM] CVE-2019-5716 wireshark: reachable assertion in fast_ensure_contiguous() from 6LoWPAN dissector
CVE-2019-5716 wireshark: reachable assertion in fast_ensure_contiguous() from 6LoWPAN dissector
In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.
References:
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15217
https://www.wireshark.org/security/wnpa-sec-2019-01.html
Upstream Patch:
https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=2b2eea1793dbff813896e1ae9dff1bedb39ee010
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1667580]
---
A reachable assertion was found in fast_ensure_contiguous() function in epan/tvbuff.c file, when called from the dissect_6lowpan() function.
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.htmlhttp://www.securityfocus.com/bid/106482https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15217https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=2b2eea1793dbff813896e1ae9dff1bedb39ee010https://lists.debian.org/debian-lts-announce/2019/01/msg00022.htmlhttps://seclists.org/bugtraq/2019/Mar/35https://www.debian.org/security/2019/dsa-4416https://www.wireshark.org/security/wnpa-sec-2019-01.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.htmlhttp://www.securityfocus.com/bid/106482https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15217https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=2b2eea1793dbff813896e1ae9dff1bedb39ee010https://lists.debian.org/debian-lts-announce/2019/01/msg00022.htmlhttps://seclists.org/bugtraq/2019/Mar/35https://www.debian.org/security/2019/dsa-4416https://www.wireshark.org/security/wnpa-sec-2019-01.html
2019-01-08
Published