Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian 9: DLA-2547-1 Moderate: Wireshark Multiple Crash Fixes

debian lts
Calendar Grey February 6, 2021
Dist Debian Esm H88
Enhance your Wireshark installations by applying essential updates from Debian LTS Advisory DLA-2548-1, which resolve various CVE vulnerabilities.
Several vulnerabilities were fixed in Wireshark, a network sniffer

Summary

CVE-2019-13619

ASN.1 BER and related dissectors crash.

CVE-2019-16319

The Gryphon dissector could go into an infinite loop.

CVE-2019-19553

The CMS dissector could crash.

CVE-2020-7045

The BT ATT dissector could crash.

CVE-2020-9428

The EAP dissector could crash.

CVE-2020-9430

The WiMax DLMAP dissector could crash.

CVE-2020-9431

The LTE RRC dissector could leak memory.

CVE-2020-11647

The BACapp dissector could crash.

CVE-2020-13164

The NFS dissector could crash.

CVE-2020-15466

The GVCP dissector could go into an infinite loop.

CVE-2020-25862

The TCP dissector could crash.

CVE-2020-25863

The MIME Multipart dissector could crash.

CVE-2020-26418

Memory leak in the Kafka protocol dissector.

CVE-2020-26421

Crash in USB HID protocol dissector.

CVE-2020-26575

The Facebook Zero Protocol (aka FBZERO) dissector
could enter an infinite loop.

CVE-2020-28030

The GQUIC dissector could crash.

For Debian 9 stretch, these problems have been fixed in version

Read the Full Advisory


Package: wireshark
Version: 2.6.20-0+deb9u1
CVE ID: CVE-2019-13619 CVE-2019-16319 CVE-2019-19553 CVE-2020-7045
Debian Bug: 958213 974688 974689

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here