cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 10 of 34
CVE-2019-9208P3HIGHCVSS 7.5fixed in wireshark 2.6.7-1 (bookworm)2019
CVE-2019-9208 [HIGH] CVE-2019-9208: wireshark - In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash.... In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash. This was addressed in epan/dissectors/asn1/tcap/tcap.cnf by avoiding NULL pointer dereferences. Scope: local bookworm: resolved (fixed in 2.6.7-1) bullseye: resolved (fixed in 2.6.7-1) forky: resolved (fixed in 2.6.7-1) sid: resolved (fixed in 2.6.7-1) trixie: resolved (fixed in 2.6.7-1
debian
CVE-2012-3825P4LOWCVSS 3.3PoCfixed in wireshark 1.6.8-1 (bookworm)2012
CVE-2012-3825 [LOW] CVE-2012-3825: wireshark - Multiple integer overflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6... Multiple integer overflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) BACapp and (2) Bluetooth HCI dissectors, a different vulnerability than CVE-2012-2392. Scope: local bookworm: resolved (fixed in 1.6.8-1) bullseye: resolved (fixed in 1.6.8-1) forky: reso
debian
CVE-2019-12295P3LOWCVSS 7.5fixed in wireshark 2.6.8-1.1 (bookworm)2019
CVE-2019-12295 [HIGH] CVE-2019-12295: wireshark - In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection... In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion. Scope: local bookworm: resolved (fixed in 2.6.8-1.1) bullseye: resolved (fixed in 2.6.8-1.1) forky: resolved (fixed in 2.6.8-1.1) sid: resolved (fixed in 2.
debian
CVE-2015-3808P3HIGHCVSS 7.8fixed in wireshark 1.12.5+g5819e5b-1 (bookworm)2015
CVE-2015-3808 [HIGH] CVE-2015-3808: wireshark - The dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR diss... The dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR dissector in Wireshark 1.12.x before 1.12.5 does not reject a zero length, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.12.5+g5819e5b-1) bullseye: resolved (fixed in 1.12.5+g5819e5b-1) forky: reso
debian
CVE-2018-14340P3HIGHCVSS 7.5fixed in wireshark 2.6.2-1 (bookworm)2018
CVE-2018-14340 [HIGH] CVE-2018-14340: wireshark - In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors tha... In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors that support zlib decompression could crash. This was addressed in epan/tvbuff_zlib.c by rejecting negative lengths to avoid a buffer over-read. Scope: local bookworm: resolved (fixed in 2.6.2-1) bullseye: resolved (fixed in 2.6.2-1) forky: resolved (fixed in 2.6.2-1) sid: resolved (fixed
debian
CVE-2018-14370P3HIGHCVSS 7.5fixed in wireshark 2.6.2-1 (bookworm)2018
CVE-2018-14370 [HIGH] CVE-2018-14370: wireshark - In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the IEEE 802.11 protocol dissect... In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/airpdcap.c via bounds checking that prevents a buffer over-read. Scope: local bookworm: resolved (fixed in 2.6.2-1) bullseye: resolved (fixed in 2.6.2-1) forky: resolved (fixed in 2.6.2-1) sid: resolved (fixed in 2.6.2-1) trixie: resolve
debian
CVE-2018-14369P3HIGHCVSS 7.5fixed in wireshark 2.6.2-1 (bookworm)2018
CVE-2018-14369 [HIGH] CVE-2018-14369: wireshark - In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the HTTP2 diss... In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the HTTP2 dissector could crash. This was addressed in epan/dissectors/packet-http2.c by verifying that header data was found before proceeding to header decompression. Scope: local bookworm: resolved (fixed in 2.6.2-1) bullseye: resolved (fixed in 2.6.2-1) forky: resolved (fixed in 2.6.2-1) sid: re
debian
CVE-2018-14343P3HIGHCVSS 7.5fixed in wireshark 2.6.2-1 (bookworm)2018
CVE-2018-14343 [HIGH] CVE-2018-14343: wireshark - In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER ... In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash. This was addressed in epan/dissectors/packet-ber.c by ensuring that length values do not exceed the maximum signed integer. Scope: local bookworm: resolved (fixed in 2.6.2-1) bullseye: resolved (fixed in 2.6.2-1) forky: resolved (fixed in 2.6.2-1) sid: resolved (
debian
CVE-2018-14344P3HIGHCVSS 7.5fixed in wireshark 2.6.2-1 (bookworm)2018
CVE-2018-14344 [HIGH] CVE-2018-14344: wireshark - In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ISMP disse... In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ISMP dissector could crash. This was addressed in epan/dissectors/packet-ismp.c by validating the IPX address length to avoid a buffer over-read. Scope: local bookworm: resolved (fixed in 2.6.2-1) bullseye: resolved (fixed in 2.6.2-1) forky: resolved (fixed in 2.6.2-1) sid: resolved (fixed in 2.
debian
CVE-2018-18227P3HIGHCVSS 7.5fixed in wireshark 2.6.4-1 (bookworm)2018
CVE-2018-18227 [HIGH] CVE-2018-18227: wireshark - In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector co... In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/dissectors/packet-mswsp.c by properly handling NULL return values. Scope: local bookworm: resolved (fixed in 2.6.4-1) bullseye: resolved (fixed in 2.6.4-1) forky: resolved (fixed in 2.6.4-1) sid: resolved (fixed in 2.6.4-1) trixie: resolved (fixed
debian
CVE-2018-11362P3HIGHCVSS 7.5fixed in wireshark 2.6.1-1 (bookworm)2018
CVE-2018-11362 [HIGH] CVE-2018-11362: wireshark - In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector coul... In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by avoiding a buffer over-read upon encountering a missing '\0' character. Scope: local bookworm: resolved (fixed in 2.6.1-1) bullseye: resolved (fixed in 2.6.1-1) forky: resolved (fixed in 2.6.1-1) sid: resolved (fixed in 2.
debian
CVE-2017-6474P3HIGHCVSS 7.5fixed in wireshark 2.2.5+g440fd4d-2 (bookworm)2017
CVE-2017-6474 [HIGH] CVE-2017-6474: wireshark - In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parse... In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by validating record sizes. Scope: local bookworm: resolved (fixed in 2.2.5+g440fd4d-2) bullseye: resolved (fixed in 2.2.5+g440fd4d-2) forky: resolved (fixed in 2.2.5+g440fd4d-2) sid: resolv
debian
CVE-2018-18225P3HIGHCVSS 7.5fixed in wireshark 2.6.4-1 (bookworm)2018
CVE-2018-18225 [HIGH] CVE-2018-18225: wireshark - In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed ... In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed. Scope: local bookworm: resolved (fixed in 2.6.4-1) bullseye: resolved (fixed in 2.6.4-1) forky: resolved (fixed in 2.6.4-1) sid: resolved (fixed in 2.6.4-1) trixie: resolved (fixed in 2.6.4-1)
debian
CVE-2020-9430P3HIGHCVSS 7.5fixed in wireshark 3.2.2-1 (bookworm)2020
CVE-2020-9430 [HIGH] CVE-2020-9430: wireshark - In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMA... In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field. Scope: local bookworm: resolved (fixed in 3.2.2-1) bullseye: resolved (fixed in 3.2.2-1) forky: resolved (fixed in 3.2.2-1) sid: resolved (fixed in 3.2.2-1) trixie: resolved (fixed
debian
CVE-2018-7335P3HIGHCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7335 [HIGH] CVE-2018-7335: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the IEEE 802.11 dissector could... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the IEEE 802.11 dissector could crash. This was addressed in epan/crypt/airpdcap.c by rejecting lengths that are too small. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2017-17084P3HIGHCVSS 7.5fixed in wireshark 2.4.3-1 (bookworm)2017
CVE-2017-17084 [HIGH] CVE-2017-17084: wireshark - In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could c... In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could crash. This was addressed in epan/dissectors/packet-iwarp-mpa.c by validating a ULPDU length. Scope: local bookworm: resolved (fixed in 2.4.3-1) bullseye: resolved (fixed in 2.4.3-1) forky: resolved (fixed in 2.4.3-1) sid: resolved (fixed in 2.4.3-1) trixie: resolved (fixed in 2.4.3-1)
debian
CVE-2017-9348P3HIGHCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9348 [HIGH] CVE-2017-9348: wireshark - In Wireshark 2.2.0 to 2.2.6, the DOF dissector could read past the end of a buff... In Wireshark 2.2.0 to 2.2.6, the DOF dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-dof.c by validating a size value. Scope: local bookworm: resolved (fixed in 2.2.7-1) bullseye: resolved (fixed in 2.2.7-1) forky: resolved (fixed in 2.2.7-1) sid: resolved (fixed in 2.2.7-1) trixie: resolved (fixed in 2.2.7-1)
debian
CVE-2017-9344P3LOWCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9344 [HIGH] CVE-2017-9344: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector c... In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector could divide by zero. This was addressed in epan/dissectors/packet-btl2cap.c by validating an interval value. Scope: local bookworm: resolved (fixed in 2.2.7-1) bullseye: resolved (fixed in 2.2.7-1) forky: resolved (fixed in 2.2.7-1) sid: resolved (fixed in 2.2.7-1) trixie: resolved (fixe
debian
CVE-2018-7419P3HIGHCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7419 [HIGH] CVE-2018-7419: wireshark - In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the NBAP dissector could crash.... In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the NBAP dissector could crash. This was addressed in epan/dissectors/asn1/nbap/nbap.cnf by ensuring DCH ID initialization. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2020-9431P3HIGHCVSS 7.5fixed in wireshark 3.2.2-1 (bookworm)2020
CVE-2020-9431 [HIGH] CVE-2020-9431: wireshark - In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC di... In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations. Scope: local bookworm: resolved (fixed in 3.2.2-1) bullseye: resolved (fixed in 3.2.2-1) forky: resolved (fixed in 3.2.2-1) sid: resolved (fixed in 3.2.2-1) trixie: r
debian
Debian Wireshark vulnerabilities | cvebase