Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malformed packet.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Oct 4, 2012 |
| Freebsd | — | Upgrade wiresharkUpgrade tsharkUpgrade wireshark-liteUpgrade tshark-lite | Dec 10, 2025 | Oct 22, 2012 |
| Oracle Solaris | — | Upgrade diagnostic/wireshark to version 1.8.3-0.175.1.3.0.1.0 on Solaris 11.1Upgrade diagnostic/wireshark/tshark to version 1.8.3-0.175.1.3.0.1.0 on Solaris 11.1Upgrade diagnostic/wireshark/wireshark-common to version 1.8.3-0.175.1.3.0.1.0 on Solaris 11.1 | May 29, 2017 | Oct 4, 2012 |
| Suse | — | Upgrade libwiretap7Upgrade libwiretap16Upgrade libwireshark19Upgrade libwireshark18Upgrade libwsutil8Upgrade libwsutil16Upgrade wireshark-gtkUpgrade libwiretap15Upgrade libwsutil7Upgrade wiresharkUpgrade wireshark-ui-qtUpgrade libwsutil17Upgrade libwireshark9Upgrade libwscodecs1Upgrade libwiretap6Upgrade libwireshark8Upgrade wireshark-devel | Aug 9, 2024 | Jul 9, 2013 |
| Wireshark | — | Upgrade to Wireshark version 1.8.3 | Oct 4, 2017 | Oct 4, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub