CVE-2019-9208: Null Pointer Dereference
Published Feb 28, 2019
·Updated
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash. This was addressed in epan/dissectors/asn1/tcap/tcap.cnf by avoiding NULL pointer dereferences.
Affected Software
5 affected componentsFixes available
debian/wireshark<=2.6.5-1~deb9u1, <=2.6.6-1
debian/wireshark
3.4.10-0+deb11u13.4.16-0+deb11u14.0.17-0+deb12u14.0.11-1~deb12u14.4.3-1
Wireshark Wireshark>=2.4.0<=2.4.12
Wireshark Wireshark>=2.6.0<=2.6.6
Debian Debian Linux=9.0
Remediation
Event History
Feb 28, 2019
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Data Sourced
via NVD·04:29 AM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:32 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·09:50 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9208?
CVE-2019-9208 is considered a moderate severity vulnerability as it can cause a crash in Wireshark.
2
How do I fix CVE-2019-9208?
To fix CVE-2019-9208, upgrade Wireshark to version 2.6.7 or later.
3
What versions of Wireshark are affected by CVE-2019-9208?
Wireshark versions 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6 are affected by CVE-2019-9208.
4
Can CVE-2019-9208 be exploited remotely?
CVE-2019-9208 does not allow for remote exploitation as it involves local processing of packets.
5
What impact does CVE-2019-9208 have on Wireshark users?
Users of Wireshark may experience application crashes when parsing specially crafted TCAP packets due to CVE-2019-9208.