CVE-2018-19628: Divide by Zero
Published Nov 29, 2018
·Updated
In Wireshark 2.6.0 to 2.6.4, the ZigBee ZCL dissector could crash. This was addressed in epan/dissectors/packet-zbee-zcl-lighting.c by preventing a divide-by-zero error.
Affected Software
3 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=2.6.0<=2.6.4
Debian Debian Linux=9.0
Remediation
Event History
Nov 29, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19628?
CVE-2018-19628 is classified as a medium severity vulnerability due to its potential to cause a denial of service via application crash.
2
How do I fix CVE-2018-19628?
To fix CVE-2018-19628, update Wireshark to version 2.6.20 or later.
3
Which versions of Wireshark are affected by CVE-2018-19628?
CVE-2018-19628 affects Wireshark versions from 2.6.0 to 2.6.4.
4
What component of Wireshark is impacted by CVE-2018-19628?
CVE-2018-19628 impacts the ZigBee ZCL dissector in Wireshark.
5
What type of vulnerability is CVE-2018-19628?
CVE-2018-19628 is a denial of service vulnerability caused by a divide-by-zero error.