CVE-2019-9209: Buffer Overflow
Published Feb 28, 2019
·Updated
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
Affected Software
11 affected componentsFixes available
debian/wireshark
3.4.10-0+deb11u13.4.16-0+deb11u14.0.17-0+deb12u14.0.11-1~deb12u14.4.3-1
Wireshark Wireshark>=2.4.0<=2.4.12
Wireshark Wireshark>=2.6.0<=2.6.6
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
openSUSE Leap=15.0
openSUSE Leap=15.1
openSUSE Leap=42.3
Remediation
Patch Available
Event History
Feb 28, 2019
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Data Sourced
via NVD·04:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:32 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·09:50 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9209?
CVE-2019-9209 is classified as a moderate severity vulnerability due to its potential to crash the Wireshark application.
2
How do I fix CVE-2019-9209?
To fix CVE-2019-9209, update to Wireshark versions 3.4.10, 3.4.16, 4.0.17, 4.0.11, or 4.4.3.
3
Which versions of Wireshark are affected by CVE-2019-9209?
Versions of Wireshark from 2.4.0 to 2.4.12 and from 2.6.0 to 2.6.6 are affected by CVE-2019-9209.
4
What impact does CVE-2019-9209 have on users?
CVE-2019-9209 can cause the Wireshark application to crash when processing certain ASN.1 BER data.
5
Is CVE-2019-9209 an issue in specific operating systems?
CVE-2019-9209 affects Wireshark on various operating systems including Debian and Ubuntu.