Debian Wireshark vulnerabilities
668 known vulnerabilities affecting debian/wireshark.
Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255
Vulnerabilities
Page 5 of 34
CVE-2011-3483P4MEDIUMCVSS 4.3PoCfixed in wireshark 1.6.2-1 (bookworm)2011
CVE-2011-3483 [MEDIUM] CVE-2011-3483: wireshark - Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of servic...
Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (application crash) via a malformed capture file that leads to an invalid root tvbuff, related to a "buffer exception handling vulnerability."
Scope: local
bookworm: resolved (fixed in 1.6.2-1)
bullseye: resolved (fixed in 1.6.2-1)
forky: resolved (fixed in 1.6.2-1)
sid: resolved (fi
debian
CVE-2020-25862P3HIGHCVSS 7.5fixed in wireshark 3.2.7-1 (bookworm)2020
CVE-2020-25862 [HIGH] CVE-2020-25862: wireshark - In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP disse...
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.
Scope: local
bookworm: resolved (fixed in 3.2.7-1)
bullseye: resolved (fixed in 3.2.7-1)
forky: resolved (fixed in 3.2.7-1)
sid: resolved (fixed in 3.2.7-1)
tri
debian
CVE-2019-10903P3LOWCVSS 7.5fixed in wireshark 2.6.8-1 (bookworm)2019
CVE-2019-10903 [HIGH] CVE-2019-10903: wireshark - In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS diss...
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.
Scope: local
bookworm: resolved (fixed in 2.6.8-1)
bullseye: resolved (fixed in 2.6.8-1)
forky: resolved (fixed in 2.6.8-1)
sid: resolved (fixed in 2.6.8-1)
trixie: resolved (fi
debian
CVE-2019-10901P3LOWCVSS 7.5fixed in wireshark 2.6.8-1 (bookworm)2019
CVE-2019-10901 [HIGH] CVE-2019-10901: wireshark - In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector coul...
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handling file digests properly.
Scope: local
bookworm: resolved (fixed in 2.6.8-1)
bullseye: resolved (fixed in 2.6.8-1)
forky: resolved (fixed in 2.6.8-1)
sid: resolved (fixed in 2.6.8-1)
trixie: resolved (fixed in 2.6.8-
debian
CVE-2021-39924P3HIGHCVSS 7.5fixed in wireshark 3.6.0-1 (bookworm)2021
CVE-2021-39924 [HIGH] CVE-2021-39924: wireshark - Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 ...
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved (fixed in 3.6.0-1)
bullseye: resolved (fixed in 3.4.10-0+deb11u1)
forky: resolved (fixed in 3.6.0-1)
sid: resolved (fixed in 3.6.0-1)
trixie: resolved (fixed in 3.6.0-1)
debian
CVE-2017-9766P3LOWCVSS 7.5fixed in wireshark 2.4.0-1 (bookworm)2017
CVE-2017-9766 [HIGH] CVE-2017-9766: wireshark - In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote a...
In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c.
Scope: local
bookworm: resolved (fixed in 2.4.0-1)
bullseye: resolved (fixed in 2.4.0-1)
forky: resolved (fixed in 2.4.0-1)
sid: resolved (fixed in 2.4.
debian
CVE-2018-14368P3HIGHCVSS 7.5fixed in wireshark 2.6.2-1 (bookworm)2018
CVE-2018-14368 [HIGH] CVE-2018-14368: wireshark - In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the Bazaar pro...
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the Bazaar protocol dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by properly handling items that are too long.
Scope: local
bookworm: resolved (fixed in 2.6.2-1)
bullseye: resolved (fixed in 2.6.2-1)
forky: resolved (fixed in 2.6.2-1)
sid: resolved (fi
debian
CVE-2018-14341P3HIGHCVSS 7.5fixed in wireshark 2.6.2-1 (bookworm)2018
CVE-2018-14341 [HIGH] CVE-2018-14341: wireshark - In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM diss...
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM dissector could go into a large or infinite loop. This was addressed in epan/dissectors/packet-dcm.c by preventing an offset overflow.
Scope: local
bookworm: resolved (fixed in 2.6.2-1)
bullseye: resolved (fixed in 2.6.2-1)
forky: resolved (fixed in 2.6.2-1)
sid: resolved (fixed in 2.6.2-1
debian
CVE-2021-39929P3HIGHCVSS 7.5fixed in wireshark 3.6.0-1 (bookworm)2021
CVE-2021-39929 [HIGH] CVE-2021-39929: wireshark - Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4....
Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved (fixed in 3.6.0-1)
bullseye: resolved (fixed in 3.4.10-0+deb11u1)
forky: resolved (fixed in 3.6.0-1)
sid: resolved (fixed in 3.6.0-1)
trixie: resolved (fixed in 3
debian
CVE-2021-4182P3HIGHCVSS 7.5fixed in wireshark 3.6.2-1 (bookworm)2021
CVE-2021-4182 [HIGH] CVE-2021-4182: wireshark - Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows de...
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved (fixed in 3.6.2-1)
bullseye: resolved (fixed in 3.4.16-0+deb11u1)
forky: resolved (fixed in 3.6.2-1)
sid: resolved (fixed in 3.6.2-1)
trixie: resolved (fixed in 3.6.2-1)
debian
CVE-2018-19622P3HIGHCVSS 7.5fixed in wireshark 2.6.5-1 (bookworm)2018
CVE-2018-19622 [HIGH] CVE-2018-19622: wireshark - In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go int...
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse.c by preventing length overflows.
Scope: local
bookworm: resolved (fixed in 2.6.5-1)
bullseye: resolved (fixed in 2.6.5-1)
forky: resolved (fixed in 2.6.5-1)
sid: resolved (fixed in 2.6.5-1)
trixie: resolved (fixed i
debian
CVE-2020-13164P3LOWCVSS 7.5fixed in wireshark 3.2.4-1 (bookworm)2020
CVE-2020-13164 [HIGH] CVE-2020-13164: wireshark - In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS disse...
In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesystem.
Scope: local
bookworm: resolved (fixed in 3.2.4-1)
bullseye: resolved (fixed in 3.2.4-1)
forky: resolved (fixed in 3.2.4-1
debian
CVE-2020-26575P3HIGHCVSS 7.5fixed in wireshark 3.2.8-0.1 (bookworm)2020
CVE-2020-26575 [HIGH] CVE-2020-26575: wireshark - In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector co...
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
Scope: local
bookworm: resolved (fixed in 3.2.8-0.1)
bullseye: resolved (fixed in 3.2.8-0.1)
forky: resolved (fixed in 3.2.8-0.1)
sid: resolved (fix
debian
CVE-2020-9428P3LOWCVSS 7.5fixed in wireshark 3.2.2-1 (bookworm)2020
CVE-2020-9428 [HIGH] CVE-2020-9428: wireshark - In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissec...
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.
Scope: local
bookworm: resolved (fixed in 3.2.2-1)
bullseye: resolved (fixed in 3.2.2-1)
forky: resolved (fixed in 3.2.2-1)
sid: resolved (fixed in 3.2.2-1)
trixie: resolved (fixed i
debian
CVE-2020-15466P3LOWCVSS 7.5fixed in wireshark 3.2.5-1 (bookworm)2020
CVE-2020-15466 [HIGH] CVE-2020-15466: wireshark - In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. ...
In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.
Scope: local
bookworm: resolved (fixed in 3.2.5-1)
bullseye: resolved (fixed in 3.2.5-1)
forky: resolved (fixed in 3.2.5-1)
sid: resolved (fixed in 3.2.5-1)
trixie: resolved (fix
debian
CVE-2017-6470P3HIGHCVSS 7.5fixed in wireshark 2.2.5+g440fd4d-2 (bookworm)2017
CVE-2017-6470 [HIGH] CVE-2017-6470: wireshark - In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop,...
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-iax2.c by constraining packet lateness.
Scope: local
bookworm: resolved (fixed in 2.2.5+g440fd4d-2)
bullseye: resolved (fixed in 2.2.5+g440fd4d-2)
forky: resolved (fixed in 2.2.5+g440
debian
CVE-2024-0208P3HIGHCVSS 7.8fixed in wireshark 4.0.17-0+deb12u1 (bookworm)2024
CVE-2024-0208 [HIGH] CVE-2024-0208: wireshark - GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 al...
GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved (fixed in 4.0.17-0+deb12u1)
bullseye: resolved (fixed in 3.4.16-0+deb11u1)
forky: resolved (fixed in 4.2.2-1)
sid: resolved (fixed in 4.2.2-1)
trixie: resolved (fixed in 4.2.2-1)
debian
CVE-2008-1563P4LOWCVSS 4.3PoCfixed in wireshark 1.0.0-1 (bookworm)2008
CVE-2008-1563 [MEDIUM] CVE-2008-1563: wireshark - The "decode as" feature in packet-bssap.c in the SCCP dissector in Wireshark (fo...
The "decode as" feature in packet-bssap.c in the SCCP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 1.0.0-1)
bullseye: resolved (fixed in 1.0.0-1)
forky: resolved (fixed in 1.0.0-1)
sid: resolved (fixed in 1.
debian
CVE-2012-4294P3MEDIUMCVSS 5.8fixed in wireshark 1.8.2-1 (bookworm)2012
CVE-2012-4294 [MEDIUM] CVE-2012-4294: wireshark - Buffer overflow in the channelised_fill_sdh_g707_format function in epan/dissect...
Buffer overflow in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a large speed (aka rate) value.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed in 1.8.2-1)
forky: resolved (fixed in 1.8.2-1)
sid: r
debian
CVE-2022-0586P3MEDIUMCVSS 6.3fixed in wireshark 3.6.2-1 (bookworm)2022
CVE-2022-0586 [MEDIUM] CVE-2022-0586: wireshark - Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 ...
Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved (fixed in 3.6.2-1)
bullseye: resolved (fixed in 3.4.16-0+deb11u1)
forky: resolved (fixed in 3.6.2-1)
sid: resolved (fixed in 3.6.2-1)
trixie: resolved (fixed in 3.6.2-1)
debian