cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 6 of 34
CVE-2022-0583P3MEDIUMCVSS 6.3fixed in wireshark 3.6.2-1 (bookworm)2022
CVE-2022-0583 [MEDIUM] CVE-2022-0583: wireshark - Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.... Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.6.2-1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 3.6.2-1) sid: resolved (fixed in 3.6.2-1) trixie: resolved (fixed in 3.6.2-1)
debian
CVE-2023-2879P3MEDIUMCVSS 6.3fixed in wireshark 4.0.6-1~deb12u1 (bookworm)2023
CVE-2023-2879 [MEDIUM] CVE-2023-2879: wireshark - GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denia... GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 4.0.6-1~deb12u1) bullseye: resolved (fixed in 3.4.16-0+deb11u1) forky: resolved (fixed in 4.0.6-1) sid: resolved (fixed in 4.0.6-1) trixie: resolved (fixed in 4.0.6-1)
debian
CVE-2012-2394P4LOWCVSS 3.3PoCfixed in wireshark 1.6.8-1 (bookworm)2012
CVE-2012-2394 [LOW] CVE-2012-2394: wireshark - Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 on the SPARC and Itanium pl... Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 on the SPARC and Itanium platforms does not properly perform data alignment for a certain structure member, which allows remote attackers to cause a denial of service (application crash) via a (1) ICMP or (2) ICMPv6 Echo Request packet. Scope: local bookworm: resolved (fixed in 1.6.8-1) bullseye: resolved (fixed in
debian
CVE-2013-4927P3LOWCVSS 7.8fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4927 [HIGH] CVE-2013-4927: wireshark - Integer signedness error in the get_type_length function in epan/dissectors/pack... Integer signedness error in the get_type_length function in epan/dissectors/packet-btsdp.c in the Bluetooth SDP dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (loop and CPU consumption) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1
debian
CVE-2013-4929P3LOWCVSS 7.8fixed in wireshark 1.10.1-1 (bookworm)2013
CVE-2013-4929 [HIGH] CVE-2013-4929: wireshark - The parseFields function in epan/dissectors/packet-dis-pdus.c in the DIS dissect... The parseFields function in epan/dissectors/packet-dis-pdus.c in the DIS dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not terminate packet-data processing after finding zero remaining bytes, which allows remote attackers to cause a denial of service (loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye:
debian
CVE-2019-16319P3LOWCVSS 7.5fixed in wireshark 3.0.4-1 (bookworm)2019
CVE-2019-16319 [HIGH] CVE-2019-16319: wireshark - In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go ... In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero. Scope: local bookworm: resolved (fixed in 3.0.4-1) bullseye: resolved (fixed in 3.0.4-1) forky: resolved (fixed in 3.0.4-1) sid: resolved (fixed in 3.0.4-1) trix
debian
CVE-2019-9214P3HIGHCVSS 7.5fixed in wireshark 2.6.7-1 (bookworm)2019
CVE-2019-9214 [HIGH] CVE-2019-9214: wireshark - In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash... In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash. This was addressed in epan/dissectors/packet-rpcap.c by avoiding an attempted dereference of a NULL conversation. Scope: local bookworm: resolved (fixed in 2.6.7-1) bullseye: resolved (fixed in 2.6.7-1) forky: resolved (fixed in 2.6.7-1) sid: resolved (fixed in 2.6.7-1) trixie: resolve
debian
CVE-2018-14339P3HIGHCVSS 7.5fixed in wireshark 2.6.2-1 (bookworm)2018
CVE-2018-14339 [HIGH] CVE-2018-14339: wireshark - In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE disse... In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE dissector could go into an infinite loop. This was addressed in epan/proto.c by adding offset and length validation. Scope: local bookworm: resolved (fixed in 2.6.2-1) bullseye: resolved (fixed in 2.6.2-1) forky: resolved (fixed in 2.6.2-1) sid: resolved (fixed in 2.6.2-1) trixie: resolved
debian
CVE-2018-16058P3LOWCVSS 7.5fixed in wireshark 2.6.3-1 (bookworm)2018
CVE-2018-16058 [HIGH] CVE-2018-16058: wireshark - In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth ... In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth AVDTP dissector could crash. This was addressed in epan/dissectors/packet-btavdtp.c by properly initializing a data structure. Scope: local bookworm: resolved (fixed in 2.6.3-1) bullseye: resolved (fixed in 2.6.3-1) forky: resolved (fixed in 2.6.3-1) sid: resolved (fixed in 2.6.3-1) tr
debian
CVE-2018-16056P3LOWCVSS 7.5fixed in wireshark 2.6.3-1 (bookworm)2018
CVE-2018-16056 [HIGH] CVE-2018-16056: wireshark - In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth ... In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by verifying that a dissector for a specific UUID exists. Scope: local bookworm: resolved (fixed in 2.6.3-1) bullseye: resolved (fixed in 2.6.3-1) forky: resolved (fixed in 2.6.3-1) sid: reso
debian
CVE-2017-9350P3LOWCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9350 [HIGH] CVE-2017-9350: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could ... In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by checking for a negative length. Scope: local bookworm: resolved (fixed in 2.2.7-1) bullseye: resolved (fixed in 2.2.7-1) forky: resolved (fixed in 2.2.7-1) sid: resolved (fixed in 2.2.7-1) trixie
debian
CVE-2017-7703P3LOWCVSS 7.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7703 [HIGH] CVE-2017-7703: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash,... In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-imap.c by calculating a line's end correctly. Scope: local bookworm: resolved (fixed in 2.2.6+g32dac6a-1) bullseye: resolved (fixed in 2.2.6+g32dac6a-1) forky: resolved (fixed in 2.2.
debian
CVE-2020-7044P3HIGHCVSS 7.5fixed in wireshark 3.2.1-1 (bookworm)2020
CVE-2020-7044 [HIGH] CVE-2020-7044: wireshark - In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addre... In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors. Scope: local bookworm: resolved (fixed in 3.2.1-1) bullseye: resolved (fixed in 3.2.1-1) forky: resolved (fixed in 3.2.1-1) sid: resolved (fixed in 3.2.1-1) trixie: resolved (fixed in 3.2.1-1)
debian
CVE-2021-39921P3HIGHCVSS 7.5fixed in wireshark 3.6.0-1 (bookworm)2021
CVE-2021-39921 [HIGH] CVE-2021-39921: wireshark - NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3... NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.6.0-1) bullseye: resolved (fixed in 3.4.10-0+deb11u1) forky: resolved (fixed in 3.6.0-1) sid: resolved (fixed in 3.6.0-1) trixie: resolved (fixed in 3.6.0-1)
debian
CVE-2021-39920P3HIGHCVSS 7.5fixed in wireshark 3.6.0-1 (bookworm)2021
CVE-2021-39920 [HIGH] CVE-2021-39920: wireshark - NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allow... NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.6.0-1) bullseye: resolved (fixed in 3.4.10-0+deb11u1) forky: resolved (fixed in 3.6.0-1) sid: resolved (fixed in 3.6.0-1) trixie: resolved (fixed in 3.6.0-1)
debian
CVE-2017-11406P3HIGHCVSS 7.5fixed in wireshark 2.4.0-1 (bookworm)2017
CVE-2017-11406 [HIGH] CVE-2017-11406: wireshark - In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS dissector could go i... In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-docsis.c by rejecting invalid Frame Control parameter values. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4.0-1) forky: resolved (fixed in 2.4.0-1) sid: resolved (fixed in 2.4.0-1) t
debian
CVE-2017-6469P3HIGHCVSS 7.5fixed in wireshark 2.2.5+g440fd4d-2 (bookworm)2017
CVE-2017-6469 [HIGH] CVE-2017-6469: wireshark - In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an LDSS dissector cras... In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an LDSS dissector crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-ldss.c by ensuring that memory is allocated for a certain data structure. Scope: local bookworm: resolved (fixed in 2.2.5+g440fd4d-2) bullseye: resolved (fixed in 2.2.5+g440fd4d-2)
debian
CVE-2017-6014P3HIGHCVSS 7.5fixed in wireshark 2.2.5+g440fd4d-2 (bookworm)2017
CVE-2017-6014 [HIGH] CVE-2017-6014: wireshark - In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file ... In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size field in a packet header is null, the offset to read from will not advance, causing continuous attempts to read the same zero length packet. This will quickly exhaust all system memory. Scope: local bookworm: resolved
debian
CVE-2017-9352P3LOWCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9352 [HIGH] CVE-2017-9352: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bazaar dissector could go i... In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bazaar dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by ensuring that backwards parsing cannot occur. Scope: local bookworm: resolved (fixed in 2.2.7-1) bullseye: resolved (fixed in 2.2.7-1) forky: resolved (fixed in 2.2.7-1) sid: resolved (fixed in 2.2.7-1) trixie: r
debian
CVE-2018-11361P3HIGHCVSS 7.5fixed in wireshark 2.6.1-1 (bookworm)2018
CVE-2018-11361 [HIGH] CVE-2018-11361: wireshark - In Wireshark 2.6.0, the IEEE 802.11 protocol dissector could crash. This was add... In Wireshark 2.6.0, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/dot11decrypt.c by avoiding a buffer overflow during FTE processing in Dot11DecryptTDLSDeriveKey. Scope: local bookworm: resolved (fixed in 2.6.1-1) bullseye: resolved (fixed in 2.6.1-1) forky: resolved (fixed in 2.6.1-1) sid: resolved (fixed in 2.6.1-1) trixie: res
debian
Debian Wireshark vulnerabilities | cvebase