CVE-2019-9209
published 2019-02-28CVE-2019-9209: In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.40%
69.7th percentile
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wireshark | < wireshark 2.6.7-1 (bookworm) | wireshark 2.6.7-1 (bookworm) |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| wireshark | wireshark | >= 0 < 2.6.7-1 | 2.6.7-1 |
| wireshark | wireshark | >= 0 < 2.6.7-1 | 2.6.7-1 |
| wireshark | wireshark | >= 0 < 2.6.7-1 | 2.6.7-1 |
| wireshark | wireshark | >= 0 < 2.6.7-1 | 2.6.7-1 |
| wireshark | wireshark | 2.4.0 – 2.4.12 | — |
| wireshark | wireshark | 2.6.0 – 2.6.6 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Wireshark vulnerabilities
vendor_ubuntu·2019-05-16
CVE-2019-10894 Wireshark vulnerabilities
Title: Wireshark vulnerabilities
Summary: Wireshark could be made to crash if it received specially crafted network
traffic or input files.
It was discovered that Wireshark improperly handled certain input. A remote or
local attacker could cause Wireshark to crash by injecting malform packets onto
the wire or convincing someone to read a malformed packet trace file.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
wireshark: Stack-based off-by-one buffer overflow in dissect_ber_GeneralizedTime
vendor_redhat·2019-01-25·CVSS 5.5
CVE-2019-9209 [MEDIUM] CWE-121 wireshark: Stack-based off-by-one buffer overflow in dissect_ber_GeneralizedTime
wireshark: Stack-based off-by-one buffer overflow in dissect_ber_GeneralizedTime
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
Statement: This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 5 and 6.
This issue affects the versions of wireshark as shipped with Red Hat Enterprise Linux 7.
Package: wireshark (Red Hat Enterprise Linux 5) - Will not fix
Package: wireshark (Red Hat Enterprise Linux 6) - Will not fix
Package: wireshark (Red Hat Enterprise Linux 7) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 8) - Fix deferred
Debian
CVE-2019-9209: wireshark - In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related disse...
vendor_debian·2019·CVSS 5.5
CVE-2019-9209 [MEDIUM] CVE-2019-9209: wireshark - In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related disse...
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
Scope: local
bookworm: resolved (fixed in 2.6.7-1)
bullseye: resolved (fixed in 2.6.7-1)
forky: resolved (fixed in 2.6.7-1)
sid: resolved (fixed in 2.6.7-1)
trixie: resolved (fixed in 2.6.7-1)
GHSA
GHSA-2cjg-pfcc-g8hr: In Wireshark 2
ghsa_unreviewed·2022-05-13
CVE-2019-9209 [MEDIUM] CWE-787 GHSA-2cjg-pfcc-g8hr: In Wireshark 2
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
OSV
CVE-2019-9209: In Wireshark 2
osv·2019-02-28·CVSS 5.5
CVE-2019-9209 [MEDIUM] CVE-2019-9209: In Wireshark 2
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.htmlhttp://www.securityfocus.com/bid/107203https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15447https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=f8fbe9f934d65b2694fa74622e5eb2e1dc8cd20bhttps://lists.debian.org/debian-lts-announce/2019/03/msg00031.htmlhttps://seclists.org/bugtraq/2019/Mar/35https://usn.ubuntu.com/3986-1/https://www.debian.org/security/2019/dsa-4416https://www.wireshark.org/security/wnpa-sec-2019-06.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.htmlhttp://www.securityfocus.com/bid/107203https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15447https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=f8fbe9f934d65b2694fa74622e5eb2e1dc8cd20bhttps://lists.debian.org/debian-lts-announce/2019/03/msg00031.htmlhttps://seclists.org/bugtraq/2019/Mar/35https://usn.ubuntu.com/3986-1/https://www.debian.org/security/2019/dsa-4416https://www.wireshark.org/security/wnpa-sec-2019-06.html
2019-02-28
Published