CVE-2019-10901: Null Pointer Dereference
Published Apr 9, 2019
·Updated
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handling file digests properly.
Affected Software
14 affected componentsFixes available
debian/wireshark
3.4.10-0+deb11u13.4.16-0+deb11u14.0.17-0+deb12u14.0.11-1~deb12u14.4.3-1
Wireshark Wireshark>=2.4.0<=2.4.13
Wireshark Wireshark>=2.6.0<=2.6.7
Wireshark Wireshark=3.0.0
Fedoraproject Fedora=29
Fedoraproject Fedora=30
Debian Debian Linux=8.0
Debian Debian Linux=9.0
openSUSE Leap=15.0
openSUSE Leap=15.1
openSUSE Leap=42.3
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Remediation
Patch Available
Event History
Apr 9, 2019
CVE Published
via MITRE·03:53 AM
Data Sourced
via MITRE·03:53 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:12 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·09:50 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-10901?
CVE-2019-10901 has a moderate severity level due to potential crashes in affected versions of Wireshark.
2
How do I fix CVE-2019-10901?
To fix CVE-2019-10901, upgrade Wireshark to versions 3.4.10 or later, 4.0.11 or later, or any fixed version as provided by your distribution.
3
Which versions of Wireshark are affected by CVE-2019-10901?
CVE-2019-10901 affects Wireshark versions 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0.
4
What component of Wireshark does CVE-2019-10901 affect?
CVE-2019-10901 specifically affects the LDSS dissector within Wireshark.
5
Is there a workaround for CVE-2019-10901?
There are no specific workarounds for CVE-2019-10901; updating to a patched version is the recommended action.