CVE-2018-19624NULL Pointer Dereference in Wireshark

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 49.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29
Latest updateMay 13

Description

In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/packet-pvfs2.c by preventing a NULL pointer dereference.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.6.5-1 (bookworm)
Debianwireshark/wireshark< 2.6.5-1+3
NVDwireshark/wireshark2.4.02.4.10+1

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

2
GHSA
GHSA-cxjm-j999-j645: In Wireshark 22022-05-13
OSV
CVE-2018-19624: In Wireshark 22018-11-29

📋Vendor Advisories

2
Red Hat
wireshark: NULL pointer dereference resulting in a PVFS dissector crash2018-11-27
Debian
CVE-2018-19624: wireshark - In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash....2018

💬Community

2
Bugzilla
CVE-2018-19624 wireshark: NULL pointer dereference resulting in a PVFS dissector crash2018-12-04
Bugzilla
CVE-2018-19622 CVE-2018-19623 CVE-2018-19624 CVE-2018-19625 CVE-2018-19626 CVE-2018-19627 CVE-2018-19628 wireshark: various flaws [fedora-all]2018-12-04