CVE-2019-9214: Null Pointer Dereference
Published Feb 28, 2019
·Updated
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash. This was addressed in epan/dissectors/packet-rpcap.c by avoiding an attempted dereference of a NULL conversation.
Affected Software
4 affected componentsFixes available
debian/wireshark
3.4.10-0+deb11u13.4.16-0+deb11u14.0.17-0+deb12u14.0.11-1~deb12u14.4.3-1
Wireshark Wireshark>=2.4.0<=2.4.12
Wireshark Wireshark>=2.6.0<=2.6.6
Debian Debian Linux=9.0
Remediation
Event History
Feb 28, 2019
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Data Sourced
via NVD·04:29 AM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:32 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·09:50 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9214?
CVE-2019-9214 is considered to be a moderate severity vulnerability due to the potential for application crashes.
2
How do I fix CVE-2019-9214?
To fix CVE-2019-9214, upgrade to a fixed version of Wireshark such as 3.4.10-0+deb11u1 or later.
3
What versions of Wireshark are affected by CVE-2019-9214?
Versions of Wireshark from 2.4.0 to 2.4.12 and from 2.6.0 to 2.6.6 are affected by CVE-2019-9214.
4
What kind of issues does CVE-2019-9214 cause?
CVE-2019-9214 can lead to application crashes due to a NULL pointer dereference in the RPCAP dissector.
5
Is there a patch available for CVE-2019-9214?
Yes, patches addressing CVE-2019-9214 have been included in the updated versions of Wireshark.