CVE-2019-5721
published 2019-01-08CVE-2019-5721: In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so…
PriorityP418medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
0.95%
57.5th percentile
In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 2.6.1-1 (bookworm) | wireshark 2.6.1-1 (bookworm) |
| wireshark | wireshark | >= 0 < 2.6.1-1 | 2.6.1-1 |
| wireshark | wireshark | >= 0 < 2.6.1-1 | 2.6.1-1 |
| wireshark | wireshark | >= 0 < 2.6.1-1 | 2.6.1-1 |
| wireshark | wireshark | >= 0 < 2.6.1-1 | 2.6.1-1 |
| wireshark | wireshark | 2.4.0 – 2.4.11 | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: use-after-free in ENIP dissector results in denial of service
vendor_redhat·2019-01-08·CVSS 5.5
CVE-2019-5721 [MEDIUM] CWE-416 wireshark: use-after-free in ENIP dissector results in denial of service
wireshark: use-after-free in ENIP dissector results in denial of service
In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.
Statement: This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: wireshark (Red Hat Enterprise Linux 5) - Not affected
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Package: wireshark (Red Hat Enterprise Linux 7) - Not affected
Package: wireshark (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2019-5721: wireshark - In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed...
vendor_debian·2019·CVSS 5.5
CVE-2019-5721 [MEDIUM] CVE-2019-5721: wireshark - In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed...
In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.
Scope: local
bookworm: resolved (fixed in 2.6.1-1)
bullseye: resolved (fixed in 2.6.1-1)
forky: resolved (fixed in 2.6.1-1)
sid: resolved (fixed in 2.6.1-1)
trixie: resolved (fixed in 2.6.1-1)
GHSA
GHSA-7gxq-23xx-mvh2: In Wireshark 2
ghsa_unreviewed·2022-05-13
CVE-2019-5721 [MEDIUM] CWE-416 GHSA-7gxq-23xx-mvh2: In Wireshark 2
In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.
OSV
CVE-2019-5721: In Wireshark 2
osv·2019-01-08·CVSS 5.5
CVE-2019-5721 [MEDIUM] CVE-2019-5721: In Wireshark 2
In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14470https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=1c66174ec7aa19e2ddc79178cf59f15a654fc4fehttps://www.wireshark.org/security/wnpa-sec-2019-05.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14470https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=1c66174ec7aa19e2ddc79178cf59f15a654fc4fehttps://www.wireshark.org/security/wnpa-sec-2019-05.html
2019-01-08
Published