CVE-2018-19622Infinite Loop in Wireshark

CWE-835Infinite Loop7 documents6 sources
Severity
7.5HIGHNVD
EPSS
1.3%
top 19.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29
Latest updateMay 13

Description

In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse.c by preventing length overflows.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.6.5-1 (bookworm)
Debianwireshark/wireshark< 2.6.5-1+3
NVDwireshark/wireshark2.4.02.4.10+1

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

2
GHSA
GHSA-4q77-2r7r-9qjc: In Wireshark 22022-05-13
OSV
CVE-2018-19622: In Wireshark 22018-11-29

📋Vendor Advisories

2
Red Hat
wireshark: Infinite loop in the MMSE dissector2018-11-27
Debian
CVE-2018-19622: wireshark - In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go int...2018

💬Community

2
Bugzilla
CVE-2018-19622 wireshark: Infinite loop in the MMSE dissector2018-12-04
Bugzilla
CVE-2018-19622 CVE-2018-19623 CVE-2018-19624 CVE-2018-19625 CVE-2018-19626 CVE-2018-19627 CVE-2018-19628 wireshark: various flaws [fedora-all]2018-12-04