CVE-2019-16319 PUBLISHED

In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero.

EPSS 0.70% · 71.9th percentile

Risk Scores

EPSS Score
0.70%
71.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSwireshark0, 2.6.10-1~ubuntu16.04.0+esm2, 2.6.10-1~ubuntu16.04.0+esm1
Ubuntu:Pro:18.04:LTSwireshark2.6.10-1~ubuntu18.04.0+esm2, 0, 2.4.2-1
Ubuntu:Pro:14.04:LTSwireshark1.10.3-1, 1.10.2-1, 0

Timeline

References

Open in Interactive Console →