CVE-2018-19623
29.11.2018, 04:29
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could crash. In addition, a remote attacker could write arbitrary data to any memory locations before the packet-scoped memory. This was addressed in epan/dissectors/packet-lbmpdm.c by disallowing certain negative values.Enginsight
| Vendor | Product | Version |
|---|---|---|
| wireshark | wireshark | 2.4.0 ≤ 𝑥 ≤ 2.4.10 |
| wireshark | wireshark | 2.6.0 ≤ 𝑥 ≤ 2.6.4 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References