CVE-2019-10894: High severity wireshark vulnerability
Published Apr 9, 2019
·Updated
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by ensuring that a valid dissector is called.
Affected Software
14 affected componentsFixes available
debian/wireshark
3.4.10-0+deb11u13.4.16-0+deb11u14.0.17-0+deb12u14.0.11-1~deb12u14.4.3-1
Wireshark Wireshark>=2.4.0<=2.4.13
Wireshark Wireshark>=2.6.0<=2.6.7
Wireshark Wireshark=3.0.0
Fedoraproject Fedora=29
Fedoraproject Fedora=30
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
openSUSE Leap=15.0
openSUSE Leap=15.1
openSUSE Leap=42.3
Remediation
Patch Available
Event History
Apr 9, 2019
CVE Published
via MITRE·03:50 AM
Data Sourced
via MITRE·03:50 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:12 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·09:50 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-10894?
CVE-2019-10894 has been classified as a medium severity vulnerability due to the potential for crashes in Wireshark.
2
How do I fix CVE-2019-10894?
To fix CVE-2019-10894, upgrade Wireshark to any of the patched versions such as 3.4.10-0+deb11u1 or later.
3
Which versions of Wireshark are affected by CVE-2019-10894?
CVE-2019-10894 affects Wireshark versions from 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and specifically version 3.0.0.
4
What component of Wireshark is impacted by CVE-2019-10894?
CVE-2019-10894 impacts the GSS-API dissector in Wireshark.
5
Is there a known workaround for CVE-2019-10894?
There is no known workaround for CVE-2019-10894 other than updating to a secure version of Wireshark.