VulnerabilityModified
CVE-2019-9209
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash.
MEDIUM 5.5EPSS 1.40%
Does this matter?
Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.
Description
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-193, CWE-787
- Affected
- wireshark/wireshark · debian/debian linux · canonical/ubuntu linux · opensuse/leap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00027.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/107203Broken Link
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15447Exploit, Issue Tracking, Patch, Vendor Advisory
- https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=f8fbe9f934d65b2694fa74622e5eb2e1dc8cd20b
- https://lists.debian.org/debian-lts-announce/2019/03/msg00031.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Mar/35Mailing List, Third Party Advisory
- https://usn.ubuntu.com/3986-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4416Third Party Advisory
- https://www.wireshark.org/security/wnpa-sec-2019-06.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00027.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/107203Broken Link
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15447Exploit, Issue Tracking, Patch, Vendor Advisory
- https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=f8fbe9f934d65b2694fa74622e5eb2e1dc8cd20b
- https://lists.debian.org/debian-lts-announce/2019/03/msg00031.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Mar/35Mailing List, Third Party Advisory
- https://usn.ubuntu.com/3986-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4416Third Party Advisory
- https://www.wireshark.org/security/wnpa-sec-2019-06.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.