CVE-2019-5716: Input Validation
Published Jan 8, 2019
·Updated
In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.
Affected Software
4 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.11-1~deb12u14.2.0-1
Wireshark Wireshark>=2.6.0<=2.6.5
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Event History
Jan 8, 2019
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-5716?
CVE-2019-5716 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2019-5716?
To fix CVE-2019-5716, update Wireshark to version 2.6.20 or later.
3
What software versions are affected by CVE-2019-5716?
CVE-2019-5716 affects Wireshark versions 2.6.0 to 2.6.5.
4
What kind of issue does CVE-2019-5716 cause?
CVE-2019-5716 can cause Wireshark to crash when the 6LoWPAN dissector is utilized.
5
Which operating systems are impacted by CVE-2019-5716?
CVE-2019-5716 impacts Debian Linux versions 8.0 and 9.0 that use affected versions of Wireshark.