Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10898

Опубликовано: 10 мар. 2019
Источник: redhat
CVSS3: 6.5

Описание

In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gsm_gsup.c by rejecting an invalid Information Element length.

Отчет

This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 8 as they did not include support for Osmocom Generic Subscriber Update Protocol (GSUP).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8wiresharkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1697955wireshark: GSUP dissector infinite loop (wnpa-sec-2019-18)

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gsm_gsup.c by rejecting an invalid Information Element length.

CVSS3: 7.5
nvd
почти 7 лет назад

In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gsm_gsup.c by rejecting an invalid Information Element length.

CVSS3: 7.5
debian
почти 7 лет назад

In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. ...

CVSS3: 7.5
github
больше 3 лет назад

In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gsm_gsup.c by rejecting an invalid Information Element length.

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость диссектора GSUP анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании

6.5 Medium

CVSS3

Уязвимость CVE-2019-10898