Alpine: multiple wireshark packages, tshark: security update to 2.4.7-r0

high Tenable Cloud Security Plugin ID 407640

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was
addressed in epan/dissectors/packet-ldss.c by avoiding a buffer over-read upon encountering a missing '\0'
character. (CVE-2018-11362)

- In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was addressed
in epan/dissectors/packet-dns.c by avoiding a NULL pointer dereference for an empty name in an SRV record.
(CVE-2018-11356)

- In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could
consume excessive memory. This was addressed in epan/tvbuff.c by rejecting negative lengths.
(CVE-2018-11357)

- In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was
addressed in epan/dissectors/packet-q931.c by avoiding a use-after-free after a malformed packet prevented
certain cleanup. (CVE-2018-11358)

- In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could
crash. This was addressed in epan/proto.c by avoiding a NULL pointer dereference. (CVE-2018-11359)

See Also

https://security.alpinelinux.org/vuln/CVE-2018-11356

https://security.alpinelinux.org/vuln/CVE-2018-11357

https://security.alpinelinux.org/vuln/CVE-2018-11358

https://security.alpinelinux.org/vuln/CVE-2018-11359

https://security.alpinelinux.org/vuln/CVE-2018-11360

https://security.alpinelinux.org/vuln/CVE-2018-11362

Plugin Details

Severity: High

ID: 407640

Version: Revision 1.26

Type: Local

Published: 10/31/2023

Updated: 12/4/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2018-11362

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/22/2018

Reference Information

CVE: CVE-2018-11356, CVE-2018-11357, CVE-2018-11358, CVE-2018-11359, CVE-2018-11360, CVE-2018-11362

BID: 104308

IAVB: 2018-B-0072-S