Infinite loop in Wireshark - #VU11513

 

Infinite loop in Wireshark - #VU11513

Published: April 4, 2018


Vulnerability identifier: #VU11513
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system..

The weakness exists due to infinite loop. A remote attacker can inject a malformed packet onto the wire or trick the victim into reading a specially crafted packet trace file, consume excessive CPU resources and cause the CQL dissector to crash.

Affected software

Wireshark

Remediation

Update to version 2.4.6 or later.


External References

Related Security Bulletins