Learn about CVE-2018-19628 affecting Wireshark versions 2.6.0 to 2.6.4. Find out the impact, technical details, affected systems, and mitigation steps for this vulnerability.
Wireshark versions 2.6.0 to 2.6.4 had a vulnerability in the ZigBee ZCL dissector that could lead to a crash. This CVE has been resolved by implementing a preventive measure against a divide-by-zero error.
Understanding CVE-2018-19628
This CVE addresses a specific vulnerability in Wireshark versions 2.6.0 to 2.6.4 related to the ZigBee ZCL dissector.
What is CVE-2018-19628?
In Wireshark versions 2.6.0 to 2.6.4, a vulnerability in the ZigBee ZCL dissector could cause the application to crash. The issue was fixed by adding a preventive measure to avoid a divide-by-zero error.
The Impact of CVE-2018-19628
The vulnerability could potentially lead to a denial of service if exploited, causing Wireshark to crash during ZigBee ZCL packet analysis.
Technical Details of CVE-2018-19628
This section provides more in-depth technical details about the CVE.
Vulnerability Description
The vulnerability in Wireshark versions 2.6.0 to 2.6.4 allowed for a crash in the ZigBee ZCL dissector due to a divide-by-zero error. The issue was specifically addressed in the file epan/dissectors/packet-zbee-zcl-lighting.c.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from CVE-2018-19628 involves taking immediate steps and implementing long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates