Buffer overflow in Wireshark - CVE-2018-11355
Published: May 29, 2018
Vulnerability identifier: #VU13027
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11355
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to buffer overflow when handling malicious input. A remote attacker can inject a malformed packet onto the wire or convince someone to read a malformed packet trace file, trigger memory corruption and cause the RTCP dissector to crash.
The weakness exists due to buffer overflow when handling malicious input. A remote attacker can inject a malformed packet onto the wire or convince someone to read a malformed packet trace file, trigger memory corruption and cause the RTCP dissector to crash.
Affected software
Wireshark
Arch Linux
Opensuse
Fedora
wireshark
Arch Linux
Opensuse
Fedora
wireshark
How to mitigate CVE-2018-11355
Update to version 2.6.1.
wireshark - addressed in versions 2.6.1-1.fc27, 2.6.1-1.fc28