FEB 03 · 2025·1 min read
One-byte heap overwrite in Wireshark's GVCP dissector
The GVCP dissector trims a trailing zero from a vendor-name field without checking length. The freed byte lands one past the end of a tvb-backed allocation. Same issue, three different versions.
High 7.8PATCHEDCVE-2025-0488
Full writeup coming soon.