Wireshark 3.0.7 released with a fix for security vulnerabilities, other bugs and with new Qt 5.12.6 for Windows and macOS installers. The Qt is a library that provides UI for Wireshark.

The Wireshark is the most popular network protocol analyzer that used by network admins and security analyst around the globe.

The Wireshark previous version was 3.0.6 and it was shipped with Qt 5.12.5, starting from Wireshark 3.0.6 with macOS it can be installed by dropping Wireshark.app onto the Applications folder.

Wireshark is a free and open-source packet analyzer and it runs on various operating systems that include Microsoft Windows, Linux, macOS, BSD, Solaris, and some other Unix-like operating systems.

The Wireshark’s first version was Etheral which was released by Gerald Combs in 1998, Ethereal trademark is owned by Network Integration Services, so he changed the name to Wireshark.

Wireshark Features

  • Data Analysis over a network connection or from already captured files
  • Wireshark GUI version let users to browser captured packers
  • Support for a range of networks that includes
  • Ethernet, IEEE 802.11, point-to-point Protocol (PPP) and loopback
  • Live USB packet capture
  • Possible to trace VoIP calls

Vulnerabilities fixed with Wireshark 3.0.7

The vulnerability with the Wireshark CMS dissector allows an attacker to inject a malformed packet into the wired network or by convincing a user to open the malformed packet trace file results in a CMS dissector crash.

It affects versions 3.0.0 to 3.0.6, 2.6.0 to 2.6.12 and fixed with 3.0.7, 2.6.13. The vulnerability can be tracked as CVE-2019-19553.

Other Bugs Fixed

  • ws_pipe_wait_for_pipe() can wait on closed handles. Bug 15696.
  • Support for 11ax in PEEKREMOTE. Bug 15740.
  • The temporary file …​ could not be opened: Invalid argument. Bug 15751.
  • Reassembling of the two TLS records is not working correctly. Bug 16109.
  • Display Filter Area: Dropdown Missing pkt_comment and tcp.options.sack_perm (likely others). Bug 16130.
  • Display Filter autocompletion should be disabled. Bug 16132.
  • BGP Linkstate IP Reachability information is incorrect. Bug 16144.
  • NGAP: ExpectedUEActivityBehaviour decode error. Bug 16145.
  • HomePlug AV dissector: MMTYPE and FMI fields are dissected incorrectly. Bug 16158.
  • JPEG files cannot be saved on Windows with french language. Bug 16165.
  • X11 –display interpreted as –display-filter which maps to -Y option. Bug 16167.
  • “Create new file automatically after” not working with extcap. Bug 16178.
  • Encrypted TLS alerts sometimes listed as decrypted. Bug 16180.
  • The “Remove Wireshark from the system path” package has “Add Wireshark to the system PATH” as its title. Bug 16200.
  • tshark -T ek -x causes get_field_data: code should not be reached. Bug 16218.
  • Crash on Go → Next/Previous Packet in Conversation when no packet is selected. Bug 16228.

Updated Protocol Support

BGP, HomePlug AV, IEEE 802.11, and TLS

The new version can be downloaded from here.

Training Course: Master in Wireshark Network Analysis – Hands-on course provides a complete network analysis Training using Wireshark.

You can follow us on LinkedinTwitterFacebook for daily Cyber Security and hacking news updates.

Gurubaran is a Security Consultant, Security Editor & Co-Founder of Cyber Security News & GBHackers On Security.