7.5
CVSSv3

CVE-2018-19622

Published: 29/11/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse.c by preventing length overflows.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer, which could result in denial of service or the execution of arbitrary code For the stable distribution (stretch), these problems have been fixed in version 265-1~deb9u1 We recommend that you upgrade your wireshark packages For the detailed security status ...
In Wireshark 260 to 262, 240 to 248, and 220 to 2216, the Radiotap dissector could crash This was addressed in epan/dissectors/packet-ieee80211-radiotap-iterc by validating iterator operations (CVE-2018-16057) In Wireshark 260 to 264 and 240 to 2410, the MMSE dissector could go into an infinite loop This was addressed in epa ...
A vulnerability in MMSE dissector allows Wireshark to loop infinitely when parsing a specially crafted pcap file Remote attacker could cause a denial of service to Wireshark by injecting malicious packets into the network that are automatically processed ...
A security issue has been found in the MMSE dissector of Wireshark versions prior to 265, which could be made to consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file ...