CVE-2019-10903: High severity wireshark vulnerability
Published Apr 9, 2019
·Updated
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.
Affected Software
14 affected componentsFixes available
debian/wireshark
3.4.10-0+deb11u13.4.16-0+deb11u14.0.17-0+deb12u14.0.11-1~deb12u14.4.3-1
Wireshark Wireshark>=2.4.0<=2.4.13
Wireshark Wireshark>=2.6.0<=2.6.7
Wireshark Wireshark=3.0.0
Fedoraproject Fedora=29
Fedoraproject Fedora=30
Debian Debian Linux=8.0
Debian Debian Linux=9.0
openSUSE Leap=15.0
openSUSE Leap=15.1
openSUSE Leap=42.3
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Remediation
Patch Available
Event History
Apr 9, 2019
CVE Published
via MITRE·03:53 AM
Data Sourced
via MITRE·03:53 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:12 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·09:50 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-10903?
CVE-2019-10903 has a moderate severity level due to its potential to crash the application.
2
How do I fix CVE-2019-10903?
To fix CVE-2019-10903, upgrade to Wireshark versions 3.4.10 or later, 4.0.11 or later, or apply the latest patches provided by your distribution.
3
Which versions of Wireshark are affected by CVE-2019-10903?
CVE-2019-10903 affects Wireshark versions from 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and the 3.0.0 version.
4
Is the CVE-2019-10903 vulnerability related to a specific protocol?
Yes, CVE-2019-10903 is specifically related to the DCERPC SPOOLSS dissector within Wireshark.
5
What platforms are impacted by CVE-2019-10903?
CVE-2019-10903 impacts multiple platforms including Debian, Ubuntu, Fedora, and openSUSE.