CVE-2019-10899: High severity wireshark vulnerability
Published Apr 9, 2019
·Updated
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was addressed in epan/dissectors/packet-srvloc.c by preventing a heap-based buffer under-read.
Affected Software
14 affected componentsFixes available
debian/wireshark
3.4.10-0+deb11u13.4.16-0+deb11u14.0.17-0+deb12u14.0.11-1~deb12u14.4.3-1
Wireshark Wireshark>=2.4.0<=2.4.13
Wireshark Wireshark>=2.6.0<=2.6.7
Wireshark Wireshark=3.0.0
Fedoraproject Fedora=29
Fedoraproject Fedora=30
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
openSUSE Leap=15.0
openSUSE Leap=15.1
openSUSE Leap=42.3
Remediation
Patch Available
Event History
Apr 9, 2019
CVE Published
via MITRE·03:52 AM
Data Sourced
via MITRE·03:52 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:12 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·09:50 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-10899?
CVE-2019-10899 has a medium severity rating as it can lead to a crash of the Wireshark application.
2
How do I fix CVE-2019-10899?
To fix CVE-2019-10899, upgrade to Wireshark version 3.4.10-0+deb11u1, 3.4.16-0+deb11u1, 4.0.17-0+deb12u1, or 4.4.3-1.
3
Which versions of Wireshark are affected by CVE-2019-10899?
CVE-2019-10899 affects Wireshark versions 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0.
4
What type of vulnerability is CVE-2019-10899?
CVE-2019-10899 is classified as a heap-based buffer under-read vulnerability in the SRVLOC dissector.
5
Who can be affected by CVE-2019-10899?
Users of Wireshark versions 2.4.x, 2.6.x, and 3.0.0 are at risk of experiencing crashes due to CVE-2019-10899.