Learn about CVE-2019-10903 affecting Wireshark versions 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0. Find out the impact, affected systems, exploitation mechanism, and mitigation steps.
Wireshark versions 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0 are affected by a boundary check issue in the DCERPC SPOOLSS dissector.
Understanding CVE-2019-10903
This CVE entry addresses a vulnerability in Wireshark versions 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0 related to the DCERPC SPOOLSS dissector.
What is CVE-2019-10903?
A boundary check was added to epan/dissectors/packet-dcerpc-spoolss.c to prevent the DCERPC SPOOLSS dissector from crashing in the affected Wireshark versions.
The Impact of CVE-2019-10903
The vulnerability could lead to a crash of the DCERPC SPOOLSS dissector in the specified versions of Wireshark.
Technical Details of CVE-2019-10903
This section provides more in-depth technical details about the CVE.
Vulnerability Description
The issue was caused by a lack of proper boundary checks in the DCERPC SPOOLSS dissector, which could result in a crash.
Affected Systems and Versions
Exploitation Mechanism
Exploiting this vulnerability could lead to a denial of service (DoS) condition by crashing the DCERPC SPOOLSS dissector.
Mitigation and Prevention
Protecting systems from CVE-2019-10903 requires specific actions to mitigate the risk.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates