CVE-2019-10895: High severity wireshark vulnerability
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10895?
CVE-2019-10895 has a medium severity rating due to the possibility of a crash in the Wireshark application.
How do I fix CVE-2019-10895?
To fix CVE-2019-10895, update to Wireshark versions 3.4.10, 3.4.16, 4.0.17, 4.0.11, or 4.4.3, or to any above 2.4.13, 2.6.7, or 3.0.0.
What types of systems are affected by CVE-2019-10895?
CVE-2019-10895 affects multiple versions of Wireshark across various platforms including Debian, Ubuntu, Fedora, and openSUSE.
What could happen if CVE-2019-10895 is exploited?
If exploited, CVE-2019-10895 could lead to an unexpected crash of the Wireshark application, potentially causing a denial of service.
What versions of Wireshark are impacted by CVE-2019-10895?
Versions of Wireshark from 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0 are impacted by CVE-2019-10895.