CVE-2018-19624: Null Pointer Dereference
Published Nov 29, 2018
·Updated
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/packet-pvfs2.c by preventing a NULL pointer dereference.
Affected Software
5 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=2.4.0<=2.4.10
Wireshark Wireshark>=2.6.0<=2.6.4
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Event History
Nov 29, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19624?
CVE-2018-19624 has a medium severity rating due to the potential crash of the Wireshark application.
2
How do I fix CVE-2018-19624?
To fix CVE-2018-19624, upgrade Wireshark to version 2.6.20 or higher, or 3.4.10 and above.
3
Which versions of Wireshark are affected by CVE-2018-19624?
Wireshark versions from 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10 are affected by CVE-2018-19624.
4
What component of Wireshark does CVE-2018-19624 affect?
CVE-2018-19624 affects the PVFS dissector in Wireshark.
5
Can CVE-2018-19624 lead to denial of service?
Yes, CVE-2018-19624 can lead to a denial of service due to application crashes.