CVE-2018-19623 — Out-of-bounds Write in Wireshark
Severity
7.5HIGHNVD
EPSS
2.1%
top 16.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 29
Latest updateMay 13
Description
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could crash. In addition, a remote attacker could write arbitrary data to any memory locations before the packet-scoped memory. This was addressed in epan/dissectors/packet-lbmpdm.c by disallowing certain negative values.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages3 packages
Also affects: Debian Linux 8.0, 9.0
🔴Vulnerability Details
2📋Vendor Advisories
2💬Community
2Bugzilla▶
CVE-2018-19623 wireshark: Heap buffer overflow in packet-lbmpdm.c:dissect_segment_ofstable() allows denial of service or possibly arbitrary code execution↗2018-12-04
Bugzilla▶
CVE-2018-19622 CVE-2018-19623 CVE-2018-19624 CVE-2018-19625 CVE-2018-19626 CVE-2018-19627 CVE-2018-19628 wireshark: various flaws [fedora-all]↗2018-12-04