Back

MEDIUM

wireshark: Stack-based off-by-one buffer overflow in dissect_ber_GeneralizedTime

Published Feb 28, 2019

Description

In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 5 and 6. This issue affects the versions of wireshark as shipped with Red Hat Enterprise Linux 7.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 28, 2019
Updated Aug 4, 2024
Reserved Feb 26, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 25, 2019