Description
In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.
References (8)
Core 8
Core References
Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15778
Vendor Advisory x_refsource_misc
https://www.wireshark.org/security/wnpa-sec-2019-19.html
Patch x_refsource_misc
https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=7b6e197da4c497e229ed3ebf6952bae5c426a820
Broken Link vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/108464
Third Party Advisory x_refsource_confirm
https://support.f5.com/csp/article/K06725231
Third Party Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/4133-1/
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K06725231?utm_source=f5support&%3Butm_medium=RSS
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/10/msg00036.html
Scores
CVSS v3
7.5
EPSS
0.0140
EPSS Percentile
80.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-674
Status
published
Products (31)
canonical/ubuntu_linux
16.04
canonical/ubuntu_linux
18.04
canonical/ubuntu_linux
19.04
debian/debian_linux
9.0
f5/big-ip_access_policy_manager
15.1.0
f5/big-ip_access_policy_manager
12.1.3.6 - 12.1.5.3
f5/big-ip_advanced_firewall_manager
15.1.0
f5/big-ip_advanced_firewall_manager
12.1.3.6 - 12.1.5.3
f5/big-ip_analytics
15.1.0
f5/big-ip_analytics
12.1.3.6 - 12.1.5.3
... and 21 more
Published
May 23, 2019
Tracked Since
Feb 18, 2026