AVIS CERTFR - 2018 - AVI - 575

AVIS CERT
CERT-FR

Publié le 29 novembre 2018 à 15h13

Objet : Multiples vulnérabilités dans Wireshark

Référence : CERTFR-2018-AVI-575

Risque(s)

- Déni de service à distance

Systèmes affectés

- Wireshark versions 2.6.x antérieures à 2.6.5
- Wireshark versions 2.4.x antérieures à 2.4.11

Résumé

De multiples vulnérabilités ont été découvertes dans Wireshark . Elles permettent à un attaquant de provoquer un déni de service à distance.

Solution

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Documentation

- Bulletin de sécurité Wireshark wnpa-sec-2018-51 du 27 novembre 2018
https://www.wireshark.org/security/wnpa-sec-2018-51.html 
- Bulletin de sécurité Wireshark wnpa-sec-2018-52 du 27 novembre 2018
https://www.wireshark.org/security/wnpa-sec-2018-52.html 
- Bulletin de sécurité Wireshark wnpa-sec-2018-53 du 27 novembre 2018
https://www.wireshark.org/security/wnpa-sec-2018-53.html 
- Bulletin de sécurité Wireshark wnpa-sec-2018-54 du 27 novembre 2018
https://www.wireshark.org/security/wnpa-sec-2018-54.html 
- Bulletin de sécurité Wireshark wnpa-sec-2018-55 du 27 novembre 2018
https://www.wireshark.org/security/wnpa-sec-2018-55.html 
- Bulletin de sécurité Wireshark wnpa-sec-2018-56 du 27 novembre 2018
https://www.wireshark.org/security/wnpa-sec-2018-56.html 
- Bulletin de sécurité Wireshark wnpa-sec-2018-57 du 27 novembre 2018
https://www.wireshark.org/security/wnpa-sec-2018-57.html 
- Référence CVE CVE-2018-19625
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19625 
- Référence CVE CVE-2018-19626
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19626 
- Référence CVE CVE-2018-19623
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19623 
- Référence CVE CVE-2018-19622
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19622 
- Référence CVE CVE-2018-19627
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19627 
- Référence CVE CVE-2018-19624
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19624 
- Référence CVE CVE-2018-19628
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19628 

Dernière version de ce document:

https://www.cert.ssi.gouv.fr/avis/CERTFR-2018-AVI-575/