CVE-2018-19625Out-of-bounds Read in Wireshark

CWE-125Out-of-bounds Read7 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
0.3%
top 49.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29
Latest updateMay 13

Description

In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_composite.c by preventing a heap-based buffer over-read.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.6.5-1 (bookworm)
Debianwireshark/wireshark< 2.6.5-1+3
NVDwireshark/wireshark2.4.02.4.10+1

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qjwp-fx53-r42v: In Wireshark 22022-05-13
OSV
CVE-2018-19625: In Wireshark 22018-11-29

📋Vendor Advisories

2
Red Hat
wireshark: Heap-based buffer over-read in the dissection engine2018-11-27
Debian
CVE-2018-19625: wireshark - In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could cra...2018

💬Community

2
Bugzilla
CVE-2018-19625 wireshark: Heap-based buffer over-read in the dissection engine2018-12-04
Bugzilla
CVE-2018-19622 CVE-2018-19623 CVE-2018-19624 CVE-2018-19625 CVE-2018-19626 CVE-2018-19627 CVE-2018-19628 wireshark: various flaws [fedora-all]2018-12-04