Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-5721

Опубликовано: 08 янв. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.

Отчет

This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 5, 6, and 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5wiresharkNot affected
Red Hat Enterprise Linux 6wiresharkNot affected
Red Hat Enterprise Linux 7wiresharkNot affected
Red Hat Enterprise Linux 8wiresharkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1666277wireshark: use-after-free in ENIP dissector results in denial of service

EPSS

Процентиль: 58%
0.00947
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.

CVSS3: 5.5
nvd
больше 7 лет назад

In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.

CVSS3: 5.5
debian
больше 7 лет назад

In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was ...

CVSS3: 5.5
github
больше 4 лет назад

In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.

CVSS3: 5.5
fstec
больше 7 лет назад

Уязвимость диссектора ENIP анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 58%
0.00947
Низкий

7.5 High

CVSS3