CVE-2019-5717: Input Validation
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the PMUL dissector could crash. This was addressed in epan/dissectors/packet-pmul.c by rejecting the invalid sequence number of zero.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5717?
CVE-2019-5717 has a medium severity rating due to the potential for denial of service through a crash of the application.
How do I fix CVE-2019-5717?
To fix CVE-2019-5717, update Wireshark to version 2.6.20 or later, or 3.4.10 or later, or apply the patch provided in the remediation notes.
Which versions of Wireshark are affected by CVE-2019-5717?
CVE-2019-5717 affects Wireshark versions 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11.
What impact does CVE-2019-5717 have on users of Wireshark?
The impact of CVE-2019-5717 on users of Wireshark is that the application may crash when processing certain packets.
Is CVE-2019-5717 specific to any operating system?
CVE-2019-5717 is not specific to any operating system but affects the Wireshark application across multiple platforms.