In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.
| Software | From | Fixed in |
|---|---|---|
| ntop / ndpi | - | 3.2.x |
| debian / debian_linux | 10.0 | 10.0.x |