Improper input validation in Wireshark - CVE-2018-19625
Published: November 30, 2018
Vulnerability identifier: #VU16190
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19625
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can inject a malformed packet into a network, to be processed by the affected application, or trick the victim into opening a malicious packet trace file and cause the Wireshark dissection engine to crash.
Affected software
Wireshark
Debian Linux
Arch Linux
Opensuse
Fedora
wireshark (Alpine package)
wireshark
Debian Linux
Arch Linux
Opensuse
Fedora
wireshark (Alpine package)
wireshark
How to mitigate CVE-2018-19625
The vulnerability has been addressed in the versions 2.4.11, 2.6.5.
Wireshark - addressed in versions 2.4.11, 2.6.5
wireshark (Alpine package) - addressed in versions 2.4.11-r0, 2.6.5-r0
wireshark - addressed in versions 2.6.5-1.fc28, 2.6.5-1.fc29
wireshark (Alpine package) - addressed in versions 2.4.11-r0, 2.6.5-r0
wireshark - addressed in versions 2.6.5-1.fc28, 2.6.5-1.fc29