==================================================================== CERT-Renater Note d'Information No. 2019/VULN380 _____________________________________________________________________ DATE : 05/12/2019 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running wireshark versions prior to 3.0.7, 2.6.13. ===================================================================== https://www.wireshark.org/security/wnpa-sec-2019-22.html _____________________________________________________________________ wnpa-sec-2019-22 ยท CMS dissector crash Summary Name: CMS dissector crash Docid: wnpa-sec-2019-22 Date: December 4, 2019 Affected versions: 3.0.0 to 3.0.6, 2.6.0 to 2.6.12 Fixed versions: 3.0.7, 2.6.13 References: Wireshark bug 15961 CVE-2019-19553 Details Description The CMS dissector could crash. Impact It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. Resolution Upgrade to Wireshark 3.0.7, 2.6.13 or later. ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================