vendor:
Wireshark
by:
Google Security Research
7.5
CVSS
HIGH
Static Out-of-Bounds Read
Not provided
CWE
Product Name: Wireshark
Affected Version From: Current git master
Affected Version To: Not provided
Patch Exists: NO
Related CWE: Not provided
CPE: Not provided
Platforms Tested:
Not provided
ASAN Crash due to Static Out-of-Bounds Read in Wireshark
The crash occurs in Wireshark's packet-zbee-zcl-general.c file during the dissection of a malformed file with tshark. It triggers a global buffer overflow error, leading to a read of 4 bytes at an out-of-bounds address.
Mitigation:
Patch or update the affected version of Wireshark.