Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Debian: DLA-1729-1 Important Security Alert: Wireshark Buffer Overflow

debian lts
Calendar Grey March 25, 2019
Dist Debian Esm H88
Update wareshark to address various security flaws such as heap corruption and endless looping in Debian LTS.
Several vulnerabilities have been found in wireshark, a network traffic analyzer

Summary

CVE-2019-9209:
Preventing the crash of the ASN.1 BER and related dissectors by
avoiding a buffer overflow associated with excessive digits in
time values.

CVE-2017-9349:
Fixing an infinite loop in the DICOM dissector by validating
a length value.

CVE-2017-9344:
Avoid a divide by zero, by validating an interval value in the
Bluetooth L2CAP dissector.


For Debian 8 "Jessie", these problems have been fixed in version
1.12.1+g01b65bf-4+deb8u18.

We recommend that you upgrade your wireshark packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
important
Lowest
Low
Medium
High
Critical

Package: wireshark
Version: 1.12.1+g01b65bf-4+deb8u18
CVE ID: CVE-2017-9344 CVE-2017-9349 CVE-2019-9209

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here