cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 12 of 34
CVE-2017-9354P4HIGHCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9354 [HIGH] CVE-2017-9354: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the RGMP dissector could crash.... In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the RGMP dissector could crash. This was addressed in epan/dissectors/packet-rgmp.c by validating an IPv4 address. Scope: local bookworm: resolved (fixed in 2.2.7-1) bullseye: resolved (fixed in 2.2.7-1) forky: resolved (fixed in 2.2.7-1) sid: resolved (fixed in 2.2.7-1) trixie: resolved (fixed in 2.2.7-1)
debian
CVE-2017-11407P4LOWCVSS 7.5fixed in wireshark 2.4.0-1 (bookworm)2017
CVE-2017-11407 [HIGH] CVE-2017-11407: wireshark - In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. T... In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fragment length before a reassembly attempt. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4.0-1) forky: resolved (fixed in 2.4.0-1) sid: resolved (fixed in 2.4.0-1) trixie: resolved
debian
CVE-2018-7420P4LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7420 [HIGH] CVE-2018-7420: wireshark - In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the pcapng file parser could cr... In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the pcapng file parser could crash. This was addressed in wiretap/pcapng.c by adding a block-size check for sysdig event blocks. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.5-
debian
CVE-2018-7336P4LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7336 [HIGH] CVE-2018-7336: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the FCP protocol dissector coul... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the FCP protocol dissector could crash. This was addressed in epan/dissectors/packet-fcp.c by checking for a NULL pointer. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2017-6468P4HIGHCVSS 7.5fixed in wireshark 2.2.5+g440fd4d-2 (bookworm)2017
CVE-2017-6468 [HIGH] CVE-2017-6468: wireshark - In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parse... In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser crash, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by validating the relationship between pages and records. Scope: local bookworm: resolved (fixed in 2.2.5+g440fd4d-2) bullseye: resolved (fixed in 2.2.5+g440fd4d-2) forky: resolved (fixed in 2.2.5+g
debian
CVE-2018-9263P4LOWCVSS 7.5fixed in wireshark 2.4.6-1 (bookworm)2018
CVE-2018-9263 [HIGH] CVE-2018-9263: wireshark - In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could cr... In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could crash. This was addressed in epan/dissectors/packet-kerberos.c by ensuring a nonzero key length. Scope: local bookworm: resolved (fixed in 2.4.6-1) bullseye: resolved (fixed in 2.4.6-1) forky: resolved (fixed in 2.4.6-1) sid: resolved (fixed in 2.4.6-1) trixie: resolved (fixed in 2.4.6-1)
debian
CVE-2018-9260P4LOWCVSS 7.5fixed in wireshark 2.4.6-1 (bookworm)2018
CVE-2018-9260 [HIGH] CVE-2018-9260: wireshark - In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector cou... In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dissectors/packet-ieee802154.c by ensuring that an allocation step occurs. Scope: local bookworm: resolved (fixed in 2.4.6-1) bullseye: resolved (fixed in 2.4.6-1) forky: resolved (fixed in 2.4.6-1) sid: resolved (fixed in 2.4.6-1) trixie: resolved (f
debian
CVE-2017-15192P4LOWCVSS 7.5fixed in wireshark 2.4.2-1 (bookworm)2017
CVE-2017-15192 [HIGH] CVE-2017-15192: wireshark - In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash... In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by considering a case where not all of the BTATT packets have the same encapsulation level. Scope: local bookworm: resolved (fixed in 2.4.2-1) bullseye: resolved (fixed in 2.4.2-1) forky: resolved (fixed in 2.4.2-1) sid: resolved (
debian
CVE-2018-9262P4LOWCVSS 7.5fixed in wireshark 2.4.6-1 (bookworm)2018
CVE-2018-9262 [HIGH] CVE-2018-9262: wireshark - In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash.... In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/packet-vlan.c by limiting VLAN tag nesting to restrict the recursion depth. Scope: local bookworm: resolved (fixed in 2.4.6-1) bullseye: resolved (fixed in 2.4.6-1) forky: resolved (fixed in 2.4.6-1) sid: resolved (fixed in 2.4.6-1) trixie: resolved
debian
CVE-2017-11408P4HIGHCVSS 7.5fixed in wireshark 2.4.0-1 (bookworm)2017
CVE-2017-11408 [HIGH] CVE-2017-11408: wireshark - In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the AMQP dissector could crash.... In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the AMQP dissector could crash. This was addressed in epan/dissectors/packet-amqp.c by checking for successful list dissection. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4.0-1) forky: resolved (fixed in 2.4.0-1) sid: resolved (fixed in 2.4.0-1) trixie: resolved (fixed in 2.4.0
debian
CVE-2017-13767P4HIGHCVSS 7.5fixed in wireshark 2.4.1-1 (bookworm)2017
CVE-2017-13767 [HIGH] CVE-2017-13767: wireshark - In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector coul... In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-msdp.c by adding length validation. Scope: local bookworm: resolved (fixed in 2.4.1-1) bullseye: resolved (fixed in 2.4.1-1) forky: resolved (fixed in 2.4.1-1) sid: resolved (fixed in 2.4.1-1) trixie: resolved (fi
debian
CVE-2018-9257P4LOWCVSS 7.5fixed in wireshark 2.4.6-1 (bookworm)2018
CVE-2018-9257 [HIGH] CVE-2018-9257: wireshark - In Wireshark 2.4.0 to 2.4.5, the CQL dissector could go into an infinite loop. T... In Wireshark 2.4.0 to 2.4.5, the CQL dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-cql.c by checking for a nonzero number of columns. Scope: local bookworm: resolved (fixed in 2.4.6-1) bullseye: resolved (fixed in 2.4.6-1) forky: resolved (fixed in 2.4.6-1) sid: resolved (fixed in 2.4.6-1) trixie: resolved (fixed in 2.4.6-1)
debian
CVE-2016-7957P4HIGHCVSS 7.5fixed in wireshark 2.2.1+ga6fbd27-1 (bookworm)2016
CVE-2016-7957 [HIGH] CVE-2016-7957: wireshark - In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by pack... In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-btl2cap.c by avoiding use of a seven-byte memcmp for potentially shorter strings. Scope: local bookworm: resolved (fixed in 2.2.1+ga6fbd27-1) bullseye: resolved (fixed in 2.2.1+ga6fbd27-1) forky: resol
debian
CVE-2017-15189P4LOWCVSS 7.5fixed in wireshark 2.4.2-1 (bookworm)2017
CVE-2017-15189 [HIGH] CVE-2017-15189: wireshark - In Wireshark 2.4.0 to 2.4.1, the DOCSIS dissector could go into an infinite loop... In Wireshark 2.4.0 to 2.4.1, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-docsis.c by adding decrements. Scope: local bookworm: resolved (fixed in 2.4.2-1) bullseye: resolved (fixed in 2.4.2-1) forky: resolved (fixed in 2.4.2-1) sid: resolved (fixed in 2.4.2-1) trixie: resolved (fixed in 2.4.2-1)
debian
CVE-2020-9429P4HIGHCVSS 7.5fixed in wireshark 3.2.2-1 (bookworm)2020
CVE-2020-9429 [HIGH] CVE-2020-9429: wireshark - In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addre... In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addressed in epan/dissectors/packet-wireguard.c by handling the situation where a certain data structure intentionally has a NULL value. Scope: local bookworm: resolved (fixed in 3.2.2-1) bullseye: resolved (fixed in 3.2.2-1) forky: resolved (fixed in 3.2.2-1) sid: resolved (fixed in 3.2.2-1)
debian
CVE-2024-0211P4HIGHCVSS 7.8fixed in wireshark 4.0.17-0+deb12u1 (bookworm)2024
CVE-2024-0211 [HIGH] CVE-2024-0211: wireshark - DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet in... DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.17-0+deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.2.2-1) sid: resolved (fixed in 4.2.2-1) trixie: resolved (fixed in 4.2.2-1)
debian
CVE-2024-0210P4LOWCVSS 7.8fixed in wireshark 4.2.2-1 (forky)2024
CVE-2024-0210 [HIGH] CVE-2024-0210: wireshark - Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packe... Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 4.2.2-1) sid: resolved (fixed in 4.2.2-1) trixie: resolved (fixed in 4.2.2-1)
debian
CVE-2024-0207P4LOWCVSS 7.8fixed in wireshark 4.2.2-1 (forky)2024
CVE-2024-0207 [HIGH] CVE-2024-0207: wireshark - HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet inj... HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 4.2.2-1) sid: resolved (fixed in 4.2.2-1) trixie: resolved (fixed in 4.2.2-1)
debian
CVE-2024-9781P4HIGHCVSS 7.8fixed in wireshark 3.4.16-0+deb11u2 (bullseye)2024
CVE-2024-9781 [HIGH] CVE-2024-9781: wireshark - AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2... AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file Scope: local bookworm: open bullseye: resolved (fixed in 3.4.16-0+deb11u2) forky: resolved (fixed in 4.4.1-1) sid: resolved (fixed in 4.4.1-1) trixie: resolved (fixed in 4.4.1-1)
debian
CVE-2023-4511P3MEDIUMCVSS 5.3fixed in wireshark 4.0.11-1~deb12u1 (bookworm)2023
CVE-2023-4511 [MEDIUM] CVE-2023-4511: wireshark - BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 a... BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.11-1~deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.8-1) sid: resolved (fixed in 4.0.8-1) trixie: resolved (fixed in 4.0.8-1)
debian
Debian Wireshark vulnerabilities | cvebase