|Type||Denial of service|
A flaw has been discovered in wireshark >= 2.6.0 and < 2.6.4 in the Steam IHS Discovery dissector where dynamically allocated memory was not properly freed on exception. This could be used by an attacker to crash wireshark by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
|12 Oct 2018||ASA-201810-9||AVG-779||wireshark-cli||High||multiple issues|
https://www.wireshark.org/security/wnpa-sec-2018-48 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15171 https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commitdiff;h=6e920ddc3cad2886ef07ca1a8e50e2a5c50986f7