cbcvebase.

Debian Wireshark vulnerabilities

668 known vulnerabilities affecting debian/wireshark.

Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255

Vulnerabilities

Page 8 of 34
CVE-2018-14367P3HIGHCVSS 7.5fixed in wireshark 2.6.2-1 (bookworm)2018
CVE-2018-14367 [HIGH] CVE-2018-14367: wireshark - In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the CoAP protocol dissector coul... In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the CoAP protocol dissector could crash. This was addressed in epan/dissectors/packet-coap.c by properly checking for a NULL condition. Scope: local bookworm: resolved (fixed in 2.6.2-1) bullseye: resolved (fixed in 2.6.2-1) forky: resolved (fixed in 2.6.2-1) sid: resolved (fixed in 2.6.2-1) trixie: resolved (fixed i
debian
CVE-2020-11647P3LOWCVSS 7.5fixed in wireshark 3.2.3-1 (bookworm)2020
CVE-2020-11647 [HIGH] CVE-2020-11647: wireshark - In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dis... In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion. Scope: local bookworm: resolved (fixed in 3.2.3-1) bullseye: resolved (fixed in 3.2.3-1) forky: resolved (fixed in 3.2.3-1) sid: resolved (fixed in 3.2.3-1) trixie: resolved (
debian
CVE-2021-22235P3HIGHCVSS 7.5fixed in wireshark 3.4.7-1 (bookworm)2021
CVE-2021-22235 [HIGH] CVE-2021-22235: wireshark - Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows de... Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file Scope: local bookworm: resolved (fixed in 3.4.7-1) bullseye: resolved (fixed in 3.4.10-0+deb11u1) forky: resolved (fixed in 3.4.7-1) sid: resolved (fixed in 3.4.7-1) trixie: resolved (fixed in 3.4.7-1)
debian
CVE-2018-18226P3HIGHCVSS 7.5fixed in wireshark 2.6.4-1 (bookworm)2018
CVE-2018-18226 [HIGH] CVE-2018-18226: wireshark - In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume sys... In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was addressed in epan/dissectors/packet-steam-ihs-discovery.c by changing the memory-management approach. Scope: local bookworm: resolved (fixed in 2.6.4-1) bullseye: resolved (fixed in 2.6.4-1) forky: resolved (fixed in 2.6.4-1) sid: resolved (fixed in 2.6.4-1) trixie
debian
CVE-2017-9343P3LOWCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9343 [HIGH] CVE-2017-9343: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the MSNIP dissector misuses a N... In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the MSNIP dissector misuses a NULL pointer. This was addressed in epan/dissectors/packet-msnip.c by validating an IPv4 address. Scope: local bookworm: resolved (fixed in 2.2.7-1) bullseye: resolved (fixed in 2.2.7-1) forky: resolved (fixed in 2.2.7-1) sid: resolved (fixed in 2.2.7-1) trixie: resolved (fixed in 2.2.7-1
debian
CVE-2017-9345P3LOWCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9345 [HIGH] CVE-2017-9345: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DNS dissector could go into... In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DNS dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dns.c by trying to detect self-referencing pointers. Scope: local bookworm: resolved (fixed in 2.2.7-1) bullseye: resolved (fixed in 2.2.7-1) forky: resolved (fixed in 2.2.7-1) sid: resolved (fixed in 2.2.7-1) trixie: resolv
debian
CVE-2017-9349P3LOWCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9349 [HIGH] CVE-2017-9349: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infi... In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value. Scope: local bookworm: resolved (fixed in 2.2.7-1) bullseye: resolved (fixed in 2.2.7-1) forky: resolved (fixed in 2.2.7-1) sid: resolved (fixed in 2.2.7-1) trixie: resolved (fixed in 2.2.7-1)
debian
CVE-2017-5596P3HIGHCVSS 7.5fixed in wireshark 2.2.4+gcc3dc1b-1 (bookworm)2017
CVE-2017-5596 [HIGH] CVE-2017-5596: wireshark - In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the ASTERIX dissector could go i... In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the ASTERIX dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-asterix.c by changing a data type to avoid an integer overflow. Scope: local bookworm: resolved (fixed in 2.2.4+gcc3dc1b-1) bullseye: resolved (fixed in 2.2.4+gcc
debian
CVE-2016-5350P3HIGHCVSS 7.5fixed in wireshark 2.0.4+gdd7746e-1 (bookworm)2016
CVE-2016-5350 [HIGH] CVE-2016-5350: wireshark - epan/dissectors/packet-dcerpc-spoolss.c in the SPOOLS component in Wireshark 1.1... epan/dissectors/packet-dcerpc-spoolss.c in the SPOOLS component in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles unexpected offsets, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. Scope: local bookworm: resolved (fixed in 2.0.4+gdd7746e-1) bullseye: resolved (fixed in 2.0.4+gdd7746e-1) forky: resolv
debian
CVE-2017-7748P3LOWCVSS 7.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7748 [HIGH] CVE-2017-7748: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into... In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by adding a length check. Scope: local bookworm: resolved (fixed in 2.2.6+g32dac6a-1) bullseye: resolved (fixed in 2.2.6+g32dac6a-1) forky: resolved (fixed in
debian
CVE-2018-7334P3HIGHCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7334 [HIGH] CVE-2018-7334: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the UMTS MAC dissector could cr... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the UMTS MAC dissector could crash. This was addressed in epan/dissectors/packet-umts_mac.c by rejecting a certain reserved value. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.
debian
CVE-2018-7418P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7418 [HIGH] CVE-2018-7418: wireshark - In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could cra... In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by correcting the extraction of the length value. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixe
debian
CVE-2017-6472P3HIGHCVSS 7.5fixed in wireshark 2.2.5+g440fd4d-2 (bookworm)2017
CVE-2017-6472 [HIGH] CVE-2017-6472: wireshark - In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector inf... In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rtmpt.c by properly incrementing a certain sequence value. Scope: local bookworm: resolved (fixed in 2.2.5+g440fd4d-2) bullseye: resolved (fixed in 2.2.5+g440fd4d-2) forky:
debian
CVE-2017-6471P3HIGHCVSS 7.5fixed in wireshark 2.2.5+g440fd4d-2 (bookworm)2017
CVE-2017-6471 [HIGH] CVE-2017-6471: wireshark - In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, t... In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by validating the capability length. Scope: local bookworm: resolved (fixed in 2.2.5+g440fd4d-2) bullseye: resolved (fixed in 2.2.5+g440fd4d-2) forky: resolved (fixed in 2.2.5+g44
debian
CVE-2017-7746P3LOWCVSS 7.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7746 [HIGH] CVE-2017-7746: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go int... In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-slsk.c by adding checks for the remaining length. Scope: local bookworm: resolved (fixed in 2.2.6+g32dac6a-1) bullseye: resolved (fixed in 2.2.6+g32dac6a-1) forky:
debian
CVE-2017-7745P3HIGHCVSS 7.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7745 [HIGH] CVE-2017-7745: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go ... In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-sigcomp.c by correcting a memory-size check. Scope: local bookworm: resolved (fixed in 2.2.6+g32dac6a-1) bullseye: resolved (fixed in 2.2.6+g32dac6a-1) forky: re
debian
CVE-2018-7323P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7323 [HIGH] CVE-2018-7323: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c h... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calculated length was monotonically increasing. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.
debian
CVE-2018-7324P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7324 [HIGH] CVE-2018-7324: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-sccp.c h... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-sccp.c had an infinite loop that was addressed by using a correct integer data type. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2018-7332P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7332 [HIGH] CVE-2018-7332: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-reload.c... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-reload.c had an infinite loop that was addressed by validating a length. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2018-7325P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7325 [HIGH] CVE-2018-7325: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpki-rtr... In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpki-rtr.c had an infinite loop that was addressed by validating a length field. Scope: local bookworm: resolved (fixed in 2.4.5-1) bullseye: resolved (fixed in 2.4.5-1) forky: resolved (fixed in 2.4.5-1) sid: resolved (fixed in 2.4.5-1) trixie: resolved (fixed in 2.4.5-1)
debian
Debian Wireshark vulnerabilities | cvebase