FEB 03 · 2025·1 min read

One-byte heap overwrite in Wireshark's GVCP dissector

The GVCP dissector trims a trailing zero from a vendor-name field without checking length. The freed byte lands one past the end of a tvb-backed allocation. Same issue, three different versions.

High 7.8PATCHEDCVE-2025-0488

Full writeup coming soon.