Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade wireshark-gnomeUpgrade wiresharkUpgrade wireshark-devel | Dec 1, 2016 | Mar 11, 2014 |
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Mar 11, 2014 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Mar 11, 2014 |
| Oracle_linux | — | Upgrade wireshark-gnomeUpgrade wiresharkUpgrade wireshark-devel | Oct 16, 2024 | Mar 11, 2014 |
| Suse | — | Upgrade libwiretap7Upgrade libwireshark8Upgrade wireshark-develUpgrade wiresharkUpgrade wireshark-gtkUpgrade wireshark-ui-qtUpgrade libwireshark9Upgrade libwiretap6Upgrade libwsutil8Upgrade libwscodecs1Upgrade libwsutil7 | Dec 18, 2015 | Mar 11, 2014 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Mar 11, 2014 |
| Wireshark | — | Upgrade to Wireshark version 1.8.13Upgrade to Wireshark version 1.10.6 | Oct 4, 2017 | Mar 11, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub