The New version of Wireshark released with the fix for vulnerabilities, number of bugs and with updated protocols support.
Wireshark is the most popular network protocol analyzer used for analyzing network packets by organizations and individuals worldwide.
With The new versions of Wireshark come with the fix for security vulnerabilities that could crash the dissector. The dissector is to decode and analyze its part of the protocol. Users requested to Upgrade to Wireshark 2.6.6 & 2.4.12 or later.
Also you can check the Master in Wireshark Network Analysis course that gives hands-on experience for troubleshooting networks using Wireshark.
Following are the vulnerabilities fixed with Wireshark 2.6.6.
CVE-2019-5716 – 6LoWPAN dissector crash
CVE-2019-5717 – P_MUL dissector could crash
CVE-2019-5718 – RTSE dissector and other ASN.1 dissectors could crash
CVE-2019-5719 – ISAKMP dissector crash
Wireshark bug 14470 – ENIP protocol dissector could crash
These vulnerabilities can be exploited by an attacker by injecting a Malformed Packet and by convincing the users to read the malformed packet trace file.
Along with the security update muliple bugs fixed.
Also the new version includes updated protocol support for following protocols 6LoWPAN, ANSI MAP, DNP3, DNS, GSM A, GTP, GTPv2, IMF, ISAKMP, ISObus VT, Kerberos, P_MUL, RTSE, S7COMM, and TCAP.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Master in Wireshark Network Analysis to keep your self-updated.
Wireshark 2.6.5 Released With Fixes for Number of Vulnerabilities that Could Crash the Wireshark
Multiple Wireshark DOS Vulnerabilities Allows a Remote Attacker to Crash Vulnerable Installations
The DrayTek Gateway devices, more specifically the Vigor2960 and Vigor300B models, are susceptible to a…
Researchers recently discovered a malicious campaign targeting Ukrainian military personnel through fake "Army+" application websites,…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert on a…
The Biden administration confirmed that a Chinese state-sponsored hacking group breached the U.S. Treasury Department,…
Security researchers Daan Keuper, Thijs Alkemade, and Khaled Nassar from Computest Sector 7 disclosed a…
Researchers observed a recent surge in activity from the "FICORA" and "CAPSAICIN," both variants of…