CVE-2019-5721: Use After Free
Published Jan 8, 2019
·Updated
In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.
Affected Software
1 affected component
Wireshark Wireshark>=2.4.0<=2.4.11
Remediation
Event History
Jan 8, 2019
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-5721?
CVE-2019-5721 has been classified as moderate severity due to the potential for crashes in Wireshark.
2
How do I fix CVE-2019-5721?
To fix CVE-2019-5721, upgrade Wireshark to version 2.4.12 or later.
3
What versions of Wireshark are affected by CVE-2019-5721?
Wireshark versions 2.4.0 to 2.4.11 are affected by CVE-2019-5721.
4
What component is impacted by CVE-2019-5721?
CVE-2019-5721 impacts the ENIP dissector component of Wireshark.
5
What type of vulnerability is CVE-2019-5721?
CVE-2019-5721 is a use-after-free vulnerability that could lead to application crashes.