CVE-2019-9208NULL Pointer Dereference in Wireshark

Severity
7.5HIGHNVD
EPSS
4.2%
top 11.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28
Latest updateMay 14

Description

In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash. This was addressed in epan/dissectors/asn1/tcap/tcap.cnf by avoiding NULL pointer dereferences.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.6.7-1 (bookworm)
Debianwireshark/wireshark< 2.6.7-1+3
NVDwireshark/wireshark2.4.02.4.12+1

Also affects: Debian Linux 9.0

🔴Vulnerability Details

2
GHSA
GHSA-h33g-839v-6v7p: In Wireshark 22022-05-14
OSV
CVE-2019-9208: In Wireshark 22019-02-28

📋Vendor Advisories

3
Ubuntu
Wireshark vulnerabilities2019-05-16
Red Hat
wireshark: null-pointer dereference in TCAP dissector2019-01-29
Debian
CVE-2019-9208: wireshark - In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash....2019

📄Research Papers

2
arXiv
Neural Transfer Learning for Repairing Security Vulnerabilities in C Code2022-01-04
arXiv
Using Sequence-to-Sequence Learning for Repairing C Vulnerabilities2019-12-04

💬Community

1
Bugzilla
CVE-2019-9208 wireshark: null-pointer dereference in TCAP dissector2019-03-04