CVE-2018-19626: Medium severity wireshark vulnerability
Published Nov 29, 2018
·Updated
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' termination.
Affected Software
5 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=2.4.0<=2.4.10
Wireshark Wireshark>=2.6.0<=2.6.4
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Event History
Nov 29, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19626?
CVE-2018-19626 has been classified as a moderate severity vulnerability due to the potential for crashing the Wireshark application.
2
How do I fix CVE-2018-19626?
To fix CVE-2018-19626, upgrade Wireshark to versions 2.6.20, 3.4.10, or 4.0.6 and above.
3
What software versions are affected by CVE-2018-19626?
Wireshark versions 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10 are vulnerable to CVE-2018-19626.
4
What is the impact of CVE-2018-19626?
CVE-2018-19626 can cause Wireshark to crash when attempting to parse certain DCOM packets.
5
Is CVE-2018-19626 present in Debian systems?
Yes, CVE-2018-19626 affects the Wireshark package on Debian systems running specific vulnerable versions.