CVE-2018-9259
04.04.2018, 07:29
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the box recursion depth.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wireshark | wireshark | 2.2.0 ≤ 𝑥 ≤ 2.2.13 |
| wireshark | wireshark | 2.4.0 ≤ 𝑥 ≤ 2.4.5 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| libwireshark8 |
| ||||||||
| libwireshark9 |
| ||||||||
| libwiretap6 |
| ||||||||
| libwiretap7 |
| ||||||||
| libwscodecs1 |
| ||||||||
| libwsutil7 |
| ||||||||
| libwsutil8 |
| ||||||||
| wireshark |
| ||||||||
| wireshark-gtk |
|
Common Weakness Enumeration
References