vendor:
Wireshark
by:
oss-fuzz project
7,5
CVSS
HIGH
Null Pointer Dereference
476
CWE
Product Name: Wireshark
Affected Version From: 2.3.0rc0-3369-g2e2ba64b72
Affected Version To: 2.3.0rc0-3369-g2e2ba64b72
Patch Exists: YES
Related CWE: N/A
CPE: a:wireshark:wireshark
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2017
Null Pointer Dereference in Wireshark
A null pointer dereference vulnerability was discovered in Wireshark, a free and open-source packet analyzer. The vulnerability exists in the dissect_routing6_rpl() function of epan/dissectors/packet-ipv6.c, which is used to dissect IPv6 routing headers. A specially crafted packet can cause a null pointer dereference, resulting in a denial of service.
Mitigation:
Upgrade to Wireshark version 2.3.0 or later.