CVE-2019-5718: Medium severity wireshark vulnerability
Published Jan 8, 2019
·Updated
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by adding a gett61string length check.
Affected Software
4 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.11-1~deb12u14.2.0-1
Wireshark Wireshark>=2.4.0<=2.4.11
Wireshark Wireshark>=2.6.0<=2.6.5
Debian Debian Linux=9.0
Remediation
Event History
Jan 8, 2019
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-5718?
CVE-2019-5718 has a medium severity rating due to the potential for application crashes.
2
How do I fix CVE-2019-5718?
To fix CVE-2019-5718, upgrade to Wireshark versions 2.6.20, 3.4.10, 4.0.11, or later.
3
What components are affected by CVE-2019-5718?
CVE-2019-5718 affects the RTSE dissector and other ASN.1 dissectors in Wireshark versions 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11.
4
Is CVE-2019-5718 applicable to all versions of Wireshark?
No, CVE-2019-5718 is only applicable to specific versions of Wireshark as mentioned in the vulnerability details.
5
Are there any known exploits for CVE-2019-5718?
There are no publicly known exploits specifically targeting CVE-2019-5718.