Total vulnerabilities in the database
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
Software | From | Fixed in |
---|---|---|
wireshark / wireshark | 2.4.0 | 2.4.12.x |
wireshark / wireshark | 2.6.0 | 2.6.6.x |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |
canonical / ubuntu_linux | 18.04 | 18.04.x |
canonical / ubuntu_linux | 18.10 | 18.10.x |
canonical / ubuntu_linux | 16.04 | 16.04.x |
opensuse / leap | 42.3 | 42.3.x |
opensuse / leap | 15.0 | 15.0.x |
opensuse / leap | 15.1 | 15.1.x |