Total vulnerabilities in the database
In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash. This was addressed in epan/tvbparse.c by limiting the recursion depth.
Software | From | Fixed in |
---|---|---|
wireshark / wireshark | 2.2.0 | 2.2.11.x |
wireshark / wireshark | 2.4.0 | 2.4.3.x |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 7.0 | 7.0.x |
debian / debian_linux | 9.0 | 9.0.x |