Double free vulnerability in the tvb_uncompress function in epan/tvbuff.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (application crash) via a packet with malformed data that uses zlib compression.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade wireshark-develUpgrade wiresharkUpgrade wireshark-gnome | Dec 1, 2016 | Jun 6, 2011 |
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Jun 6, 2011 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Jun 6, 2011 |
| Oracle_linux | — | Upgrade wireshark-develUpgrade wiresharkUpgrade wireshark-gnome | Oct 16, 2024 | Jun 6, 2011 |
| Suse | — | Upgrade libwireshark19Upgrade libwsutil8Upgrade libwsutil16Upgrade libwscodecs1Upgrade libwireshark9Upgrade libwiretap6Upgrade libwireshark8Upgrade libwireshark18Upgrade wireshark-gtkUpgrade wireshark-ui-qtUpgrade libwsutil7Upgrade libwiretap7Upgrade libwiretap15Upgrade wiresharkUpgrade libwiretap16Upgrade wireshark-develUpgrade libwsutil17 | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Jun 6, 2011 |
| Wireshark | — | Upgrade to Wireshark version 1.2.17Upgrade to Wireshark version 1.4.7 | Oct 4, 2017 | Jun 6, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub