Back

HIGH

wireshark: Heap buffer overflow in packet-lbmpdm.c:dissect_segment_ofstable() allows denial of service or possibly arbitrary code execution

Published Nov 29, 2018

Description

In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could crash. In addition, a remote attacker could write arbitrary data to any memory locations before the packet-scoped memory. This was addressed in epan/dissectors/packet-lbmpdm.c by disallowing certain negative values.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 5, 6 and 7 as they did not include LBMPDM dissector where the vulnerability occurred.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 29, 2018
Updated Aug 5, 2024
Reserved Nov 28, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 27, 2018