CVE-2018-19628Divide By Zero in Wireshark

CWE-369Divide By Zero7 documents6 sources
Severity
7.5HIGHNVD
EPSS
0.9%
top 24.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29
Latest updateMay 13

Description

In Wireshark 2.6.0 to 2.6.4, the ZigBee ZCL dissector could crash. This was addressed in epan/dissectors/packet-zbee-zcl-lighting.c by preventing a divide-by-zero error.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.6.5-1 (bookworm)
Debianwireshark/wireshark< 2.6.5-1+3
NVDwireshark/wireshark2.6.02.6.4

Also affects: Debian Linux 9.0

🔴Vulnerability Details

2
GHSA
GHSA-65vm-8gfc-9p94: In Wireshark 22022-05-13
OSV
CVE-2018-19628: In Wireshark 22018-11-29

📋Vendor Advisories

2
Red Hat
wireshark: ZigBee ZCL dissector crash2018-11-27
Debian
CVE-2018-19628: wireshark - In Wireshark 2.6.0 to 2.6.4, the ZigBee ZCL dissector could crash. This was addr...2018

💬Community

2
Bugzilla
CVE-2018-19622 CVE-2018-19623 CVE-2018-19624 CVE-2018-19625 CVE-2018-19626 CVE-2018-19627 CVE-2018-19628 wireshark: various flaws [fedora-all]2018-12-04
Bugzilla
CVE-2018-19628 wireshark: ZigBee ZCL dissector crash2018-12-04