CVE-2018-7419: High severity Wireshark Wireshark vulnerability
In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the NBAP dissector could crash. This was addressed in epan/dissectors/asn1/nbap/nbap.cnf by ensuring DCH ID initialization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/wiresharkto a version that resolves this vulnerability.Fixed in 2.6.20-0+deb10u4Fixed in 2.6.20-0+deb10u7Fixed in 3.4.10-0+deb11u1Fixed in 4.0.6-1~deb12u1Fixed in 4.0.10-1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7419?
CVE-2018-7419 is considered to be a moderate severity vulnerability as it can cause the Wireshark application to crash.
How do I fix CVE-2018-7419?
To fix CVE-2018-7419, upgrade Wireshark to version 2.6.20-0+deb10u4 or later, or any of the fixed versions such as 2.4.10 or 4.0.6.
What versions of Wireshark are affected by CVE-2018-7419?
CVE-2018-7419 affects Wireshark versions from 2.2.0 to 2.2.12 and from 2.4.0 to 2.4.4.
Which operating systems are impacted by CVE-2018-7419?
CVE-2018-7419 impacts Debian GNU/Linux versions 7.0, 8.0, and 9.0 that have the affected versions of Wireshark installed.
What component of Wireshark does CVE-2018-7419 affect?
CVE-2018-7419 specifically affects the NBAP dissector in Wireshark.