Debian Wireshark vulnerabilities
668 known vulnerabilities affecting debian/wireshark.
Total CVEs
668
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH129MEDIUM276LOW255
Vulnerabilities
Page 8 of 34
CVE-2018-14367P3HIGHCVSS 7.5fixed in wireshark 2.6.2-1 (bookworm)2018
CVE-2018-14367 [HIGH] CVE-2018-14367: wireshark - In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the CoAP protocol dissector coul...
In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the CoAP protocol dissector could crash. This was addressed in epan/dissectors/packet-coap.c by properly checking for a NULL condition.
Scope: local
bookworm: resolved (fixed in 2.6.2-1)
bullseye: resolved (fixed in 2.6.2-1)
forky: resolved (fixed in 2.6.2-1)
sid: resolved (fixed in 2.6.2-1)
trixie: resolved (fixed i
debian
CVE-2020-11647P3LOWCVSS 7.5fixed in wireshark 3.2.3-1 (bookworm)2020
CVE-2020-11647 [HIGH] CVE-2020-11647: wireshark - In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dis...
In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.
Scope: local
bookworm: resolved (fixed in 3.2.3-1)
bullseye: resolved (fixed in 3.2.3-1)
forky: resolved (fixed in 3.2.3-1)
sid: resolved (fixed in 3.2.3-1)
trixie: resolved (
debian
CVE-2021-22235P3HIGHCVSS 7.5fixed in wireshark 3.4.7-1 (bookworm)2021
CVE-2021-22235 [HIGH] CVE-2021-22235: wireshark - Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows de...
Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved (fixed in 3.4.7-1)
bullseye: resolved (fixed in 3.4.10-0+deb11u1)
forky: resolved (fixed in 3.4.7-1)
sid: resolved (fixed in 3.4.7-1)
trixie: resolved (fixed in 3.4.7-1)
debian
CVE-2018-18226P3HIGHCVSS 7.5fixed in wireshark 2.6.4-1 (bookworm)2018
CVE-2018-18226 [HIGH] CVE-2018-18226: wireshark - In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume sys...
In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was addressed in epan/dissectors/packet-steam-ihs-discovery.c by changing the memory-management approach.
Scope: local
bookworm: resolved (fixed in 2.6.4-1)
bullseye: resolved (fixed in 2.6.4-1)
forky: resolved (fixed in 2.6.4-1)
sid: resolved (fixed in 2.6.4-1)
trixie
debian
CVE-2017-9343P3LOWCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9343 [HIGH] CVE-2017-9343: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the MSNIP dissector misuses a N...
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the MSNIP dissector misuses a NULL pointer. This was addressed in epan/dissectors/packet-msnip.c by validating an IPv4 address.
Scope: local
bookworm: resolved (fixed in 2.2.7-1)
bullseye: resolved (fixed in 2.2.7-1)
forky: resolved (fixed in 2.2.7-1)
sid: resolved (fixed in 2.2.7-1)
trixie: resolved (fixed in 2.2.7-1
debian
CVE-2017-9345P3LOWCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9345 [HIGH] CVE-2017-9345: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DNS dissector could go into...
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DNS dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dns.c by trying to detect self-referencing pointers.
Scope: local
bookworm: resolved (fixed in 2.2.7-1)
bullseye: resolved (fixed in 2.2.7-1)
forky: resolved (fixed in 2.2.7-1)
sid: resolved (fixed in 2.2.7-1)
trixie: resolv
debian
CVE-2017-9349P3LOWCVSS 7.5fixed in wireshark 2.2.7-1 (bookworm)2017
CVE-2017-9349 [HIGH] CVE-2017-9349: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infi...
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value.
Scope: local
bookworm: resolved (fixed in 2.2.7-1)
bullseye: resolved (fixed in 2.2.7-1)
forky: resolved (fixed in 2.2.7-1)
sid: resolved (fixed in 2.2.7-1)
trixie: resolved (fixed in 2.2.7-1)
debian
CVE-2017-5596P3HIGHCVSS 7.5fixed in wireshark 2.2.4+gcc3dc1b-1 (bookworm)2017
CVE-2017-5596 [HIGH] CVE-2017-5596: wireshark - In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the ASTERIX dissector could go i...
In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the ASTERIX dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-asterix.c by changing a data type to avoid an integer overflow.
Scope: local
bookworm: resolved (fixed in 2.2.4+gcc3dc1b-1)
bullseye: resolved (fixed in 2.2.4+gcc
debian
CVE-2016-5350P3HIGHCVSS 7.5fixed in wireshark 2.0.4+gdd7746e-1 (bookworm)2016
CVE-2016-5350 [HIGH] CVE-2016-5350: wireshark - epan/dissectors/packet-dcerpc-spoolss.c in the SPOOLS component in Wireshark 1.1...
epan/dissectors/packet-dcerpc-spoolss.c in the SPOOLS component in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles unexpected offsets, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.4+gdd7746e-1)
bullseye: resolved (fixed in 2.0.4+gdd7746e-1)
forky: resolv
debian
CVE-2017-7748P3LOWCVSS 7.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7748 [HIGH] CVE-2017-7748: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into...
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by adding a length check.
Scope: local
bookworm: resolved (fixed in 2.2.6+g32dac6a-1)
bullseye: resolved (fixed in 2.2.6+g32dac6a-1)
forky: resolved (fixed in
debian
CVE-2018-7334P3HIGHCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7334 [HIGH] CVE-2018-7334: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the UMTS MAC dissector could cr...
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the UMTS MAC dissector could crash. This was addressed in epan/dissectors/packet-umts_mac.c by rejecting a certain reserved value.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.4.5-1)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixed in 2.4.
debian
CVE-2018-7418P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7418 [HIGH] CVE-2018-7418: wireshark - In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could cra...
In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by correcting the extraction of the length value.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.4.5-1)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixe
debian
CVE-2017-6472P3HIGHCVSS 7.5fixed in wireshark 2.2.5+g440fd4d-2 (bookworm)2017
CVE-2017-6472 [HIGH] CVE-2017-6472: wireshark - In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector inf...
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rtmpt.c by properly incrementing a certain sequence value.
Scope: local
bookworm: resolved (fixed in 2.2.5+g440fd4d-2)
bullseye: resolved (fixed in 2.2.5+g440fd4d-2)
forky:
debian
CVE-2017-6471P3HIGHCVSS 7.5fixed in wireshark 2.2.5+g440fd4d-2 (bookworm)2017
CVE-2017-6471 [HIGH] CVE-2017-6471: wireshark - In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, t...
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by validating the capability length.
Scope: local
bookworm: resolved (fixed in 2.2.5+g440fd4d-2)
bullseye: resolved (fixed in 2.2.5+g440fd4d-2)
forky: resolved (fixed in 2.2.5+g44
debian
CVE-2017-7746P3LOWCVSS 7.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7746 [HIGH] CVE-2017-7746: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go int...
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-slsk.c by adding checks for the remaining length.
Scope: local
bookworm: resolved (fixed in 2.2.6+g32dac6a-1)
bullseye: resolved (fixed in 2.2.6+g32dac6a-1)
forky:
debian
CVE-2017-7745P3HIGHCVSS 7.5fixed in wireshark 2.2.6+g32dac6a-1 (bookworm)2017
CVE-2017-7745 [HIGH] CVE-2017-7745: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go ...
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-sigcomp.c by correcting a memory-size check.
Scope: local
bookworm: resolved (fixed in 2.2.6+g32dac6a-1)
bullseye: resolved (fixed in 2.2.6+g32dac6a-1)
forky: re
debian
CVE-2018-7323P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7323 [HIGH] CVE-2018-7323: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c h...
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calculated length was monotonically increasing.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.4.5-1)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixed in 2.
debian
CVE-2018-7324P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7324 [HIGH] CVE-2018-7324: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-sccp.c h...
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-sccp.c had an infinite loop that was addressed by using a correct integer data type.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.4.5-1)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2018-7332P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7332 [HIGH] CVE-2018-7332: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-reload.c...
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-reload.c had an infinite loop that was addressed by validating a length.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.4.5-1)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixed in 2.4.5-1)
debian
CVE-2018-7325P3LOWCVSS 7.5fixed in wireshark 2.4.5-1 (bookworm)2018
CVE-2018-7325 [HIGH] CVE-2018-7325: wireshark - In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpki-rtr...
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpki-rtr.c had an infinite loop that was addressed by validating a length field.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.4.5-1)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixed in 2.4.5-1)
debian