CVE-2019-19553: High severity wireshark vulnerability
Published Dec 5, 2019
·Updated
In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection.
Affected Software
6 affected components
Wireshark Wireshark>=2.6.0<=2.6.12
Wireshark Wireshark>=3.0.0<=3.0.6
openSUSE Leap=15.1
Oracle Solaris=11
Oracle ZFS Storage Appliance=8.8
Debian Debian Linux=9.0
Remediation
Event History
Dec 5, 2019
CVE Published
via MITRE·12:58 AM
Data Sourced
via MITRE·12:58 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Wireshark vulnerability?
The vulnerability ID for this Wireshark vulnerability is CVE-2019-19553.
2
Which versions of Wireshark are affected by this vulnerability?
Wireshark versions 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12 are affected by this vulnerability.
3
How does the vulnerability manifest?
The vulnerability manifests as a crash in the CMS dissector in Wireshark.
4
What is the severity of CVE-2019-19553?
The severity of CVE-2019-19553 is high with a CVSS score of 7.5.
5
How was the vulnerability addressed?
The vulnerability was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection.