Debian Wireshark vulnerabilities
668 known vulnerabilities affecting debian/wireshark.
Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255
Vulnerabilities
Page 11 of 34
CVE-2017-7704P3HIGHCVSS 7.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7704 [HIGH] CVE-2017-7704: wireshark - In Wireshark 2.2.0 to 2.2.5, the DOF dissector could go into an infinite loop, t...
In Wireshark 2.2.0 to 2.2.5, the DOF dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-dof.c by using a different integer data type and adjusting a return value.
Scope: local
bookworm: resolved (fixed in 2.2.6+g32dac6a-1)
bullseye: resolved (fixed in 2.2.6+g32dac6a-1)
for
debian
CVE-2017-15191P3LOWCVSS 7.5fixed in wireshark 2.4.2-1 (bookworm)2017
CVE-2017-15191 [HIGH] CVE-2017-15191: wireshark - In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissec...
In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length.
Scope: local
bookworm: resolved (fixed in 2.4.2-1)
bullseye: resolved (fixed in 2.4.2-1)
forky: resolved (fixed in 2.4.2-1)
sid: resolved (fixed in 2.4.2-1)
trixie: resolved (fixed in 2.4
debian
CVE-2018-5336P3HIGHCVSS 7.5fixed in wireshark 2.4.4-1 (bookworm)2018
CVE-2018-5336 [HIGH] CVE-2018-5336: wireshark - In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and G...
In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash. This was addressed in epan/tvbparse.c by limiting the recursion depth.
Scope: local
bookworm: resolved (fixed in 2.4.4-1)
bullseye: resolved (fixed in 2.4.4-1)
forky: resolved (fixed in 2.4.4-1)
sid: resolved (fixed in 2.4.4-1)
trixie: resolved (fixed in 2.4.4-
debian
CVE-2018-7320P3HIGHCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7320 [HIGH] CVE-2018-7320: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the SIGCOMP protocol dissector ...
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the SIGCOMP protocol dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by validating operand offsets.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.4.5-1)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixed in 2.4.5
debian
CVE-2018-7337P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7337 [HIGH] CVE-2018-7337: wireshark - In Wireshark 2.4.0 to 2.4.4, the DOCSIS protocol dissector could crash. This was...
In Wireshark 2.4.0 to 2.4.4, the DOCSIS protocol dissector could crash. This was addressed in plugins/docsis/packet-docsis.c by removing the recursive algorithm that had been used for concatenated PDUs.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.4.5-1)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie:
debian
CVE-2017-6473P3HIGHCVSS 7.5fixed in wireshark 2.2.5+g440fd4d-2 (bookworm)2017
CVE-2017-6473 [HIGH] CVE-2017-6473: wireshark - In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a K12 file parser cras...
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a K12 file parser crash, triggered by a malformed capture file. This was addressed in wiretap/k12.c by validating the relationships between lengths and offsets.
Scope: local
bookworm: resolved (fixed in 2.2.5+g440fd4d-2)
bullseye: resolved (fixed in 2.2.5+g440fd4d-2)
forky: resolved (fixed in 2.2.5+g440fd4d-2
debian
CVE-2017-15193P3LOWCVSS 7.5fixed in wireshark 2.4.2-1 (bookworm)2017
CVE-2017-15193 [HIGH] CVE-2017-15193: wireshark - In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the MBIM dissector could crash o...
In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the MBIM dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-mbim.c by changing the memory-allocation approach.
Scope: local
bookworm: resolved (fixed in 2.4.2-1)
bullseye: resolved (fixed in 2.4.2-1)
forky: resolved (fixed in 2.4.2-1)
sid: resolved (fixed in 2.4.2-1)
trixie:
debian
CVE-2017-6467P3HIGHCVSS 7.5fixed in wireshark 2.2.5+g440fd4d-2 (bookworm)2017
CVE-2017-6467 [HIGH] CVE-2017-6467: wireshark - In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a Netscaler file parse...
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a Netscaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by changing the restrictions on file size.
Scope: local
bookworm: resolved (fixed in 2.2.5+g440fd4d-2)
bullseye: resolved (fixed in 2.2.5+g440fd4d-2)
forky: resolved (fixed in 2.2.5+g440fd4d
debian
CVE-2018-7322P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7322 [HIGH] CVE-2018-7322: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-dcm.c ha...
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-dcm.c had an infinite loop that was addressed by checking for integer wraparound.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.4.5-1)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2017-11409P3LOWCVSS 7.5fixed in wireshark 2.2.0~rc1+g438c022-1 (bookworm)2017
CVE-2017-11409 [HIGH] CVE-2017-11409: wireshark - In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop....
In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/packet-gprs-llc.c by using a different integer data type.
Scope: local
bookworm: resolved (fixed in 2.2.0~rc1+g438c022-1)
bullseye: resolved (fixed in 2.2.0~rc1+g438c022-1)
forky: resolved (fixed in 2.2.0~rc1+g438c022-1)
sid: resolved (fixed in 2.
debian
CVE-2018-7330P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7330 [HIGH] CVE-2018-7330: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thread.c...
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thread.c had an infinite loop that was addressed by using a correct integer data type.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.4.5-1)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2018-7329P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7329 [HIGH] CVE-2018-7329: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-s7comm.c...
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-s7comm.c had an infinite loop that was addressed by correcting off-by-one errors.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.4.5-1)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2017-5597P3HIGHCVSS 7.5fixed in wireshark 2.2.4+gcc3dc1b-1 (bookworm)2017
CVE-2017-5597 [HIGH] CVE-2017-5597: wireshark - In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the DHCPv6 dissector could go in...
In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the DHCPv6 dissector could go into a large loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-dhcpv6.c by changing a data type to avoid an integer overflow.
Scope: local
bookworm: resolved (fixed in 2.2.4+gcc3dc1b-1)
bullseye: resolved (fixed in 2.2.4+gcc3dc1b-
debian
CVE-2017-17997P3HIGHCVSS 7.5fixed in wireshark 2.4.0-1 (bookworm)2017
CVE-2017-17997 [HIGH] CVE-2017-17997: wireshark - In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and cras...
In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and crashes. This was addressed in epan/dissectors/packet-mrdisc.c by validating an IPv4 address. This vulnerability is similar to CVE-2017-9343.
Scope: local
bookworm: resolved (fixed in 2.4.0-1)
bullseye: resolved (fixed in 2.4.0-1)
forky: resolved (fixed in 2.4.0-1)
sid: resolved (fixed in
debian
CVE-2018-7421P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7421 [HIGH] CVE-2018-7421: wireshark - In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the DMP dissector could go into...
In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the DMP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dmp.c by correctly supporting a bounded number of Security Categories for a DMP Security Classification.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.4.5-1)
forky: resolved (fixed in 2.4.
debian
CVE-2021-39923P3HIGHCVSS 7.5fixed in wireshark 3.6.0-1 (bookworm)2021
CVE-2021-39923 [HIGH] CVE-2021-39923: wireshark - Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17...
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved (fixed in 3.6.0-1)
bullseye: resolved (fixed in 3.4.10-0+deb11u1)
forky: resolved (fixed in 3.6.0-1)
sid: resolved (fixed in 3.6.0-1)
trixie: resolved (fixed in 3.6.0-1)
debian
CVE-2017-11410P3HIGHCVSS 7.5fixed in wireshark 2.4.0-1 (bookworm)2017
CVE-2017-11410 [HIGH] CVE-2017-11410: wireshark - In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could g...
In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wbxml.c by adding validation of the relationships between indexes and lengths. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-7702
debian
CVE-2022-3725P3MEDIUMCVSS 6.3fixed in wireshark 4.0.0-1 (bookworm)2022
CVE-2022-3725 [MEDIUM] CVE-2022-3725: wireshark - Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial o...
Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved (fixed in 4.0.0-1)
bullseye: resolved
forky: resolved (fixed in 4.0.0-1)
sid: resolved (fixed in 4.0.0-1)
trixie: resolved (fixed in 4.0.0-1)
debian
CVE-2017-17935P4HIGHCVSS 7.5fixed in wireshark 2.4.4-1 (bookworm)2017
CVE-2017-17935 [HIGH] CVE-2017-17935: wireshark - The File_read_line function in epan/wslua/wslua_file.c in Wireshark through 2.2....
The File_read_line function in epan/wslua/wslua_file.c in Wireshark through 2.2.11 does not properly strip '\n' characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet that triggers the attempted processing of an empty line.
Scope: local
bookworm: resolved (fixed in 2.4.4-1)
bullseye: res
debian
CVE-2018-11357P4HIGHCVSS 7.5fixed in wireshark 2.6.1-1 (bookworm)2018
CVE-2018-11357 [HIGH] CVE-2018-11357: wireshark - In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and o...
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. This was addressed in epan/tvbuff.c by rejecting negative lengths.
Scope: local
bookworm: resolved (fixed in 2.6.1-1)
bullseye: resolved (fixed in 2.6.1-1)
forky: resolved (fixed in 2.6.1-1)
sid: resolved (fixed in 2.6.1-1)
trixie: resolv
debian