CVE-2018-7417
- EPSS 0.4%
- Veröffentlicht 23.02.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:05
In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the IPMI dissector could crash. This was addressed in epan/dissectors/packet-ipmi-picmg.c by adding support for crafted packets that lack an IPMI header.
CVE-2018-7418
- EPSS 1.01%
- Veröffentlicht 23.02.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:05
In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by correcting the extraction of the length value.
CVE-2018-7419
- EPSS 2.02%
- Veröffentlicht 23.02.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:06
In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the NBAP dissector could crash. This was addressed in epan/dissectors/asn1/nbap/nbap.cnf by ensuring DCH ID initialization.
CVE-2018-7420
- EPSS 2.02%
- Veröffentlicht 23.02.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:06
In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the pcapng file parser could crash. This was addressed in wiretap/pcapng.c by adding a block-size check for sysdig event blocks.
CVE-2018-7421
- EPSS 0.43%
- Veröffentlicht 23.02.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:06
In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the DMP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dmp.c by correctly supporting a bounded number of Security Categories for a DMP Security Classification.
CVE-2018-7320
- EPSS 0.7%
- Veröffentlicht 23.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:00
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the SIGCOMP protocol dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by validating operand offsets.
CVE-2018-7321
- EPSS 0.43%
- Veröffentlicht 23.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:00
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with dissection after encountering an unexpected type.
CVE-2018-7322
- EPSS 0.54%
- Veröffentlicht 23.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:00
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-dcm.c had an infinite loop that was addressed by checking for integer wraparound.
CVE-2018-7323
- EPSS 0.54%
- Veröffentlicht 23.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:00
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calculated length was monotonically increasing.
CVE-2018-7324
- EPSS 0.54%
- Veröffentlicht 23.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:01
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-sccp.c had an infinite loop that was addressed by using a correct integer data type.