Memory corruption in Wireshark - CVE-2018-16057

 

Memory corruption in Wireshark - CVE-2018-16057

Published: August 30, 2018 / Updated: August 31, 2018


Vulnerability identifier: #VU14578
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16057
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to boundary error in the ieee80211_radiotap_iterator_next() function, as defined in the epan/dissectors/packet-ieee80211-radiotap-iter.c source code file. A remote attacker can inject a malformed packet into a network, to be processed by the affected application, or trick the victim into opening a malicious packet trace file and cause the Radiotap dissector component to crash.


Affected software

Wireshark
Debian Linux
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Opensuse
Fedora
wireshark (Red Hat package)
wireshark (Alpine package)
wireshark

How to mitigate CVE-2018-16057

The vulnerability has been fixed in the versions 2.6.3, 2.4.9, 2.2.17.

Wireshark - addressed in versions 2.2.17, 2.4.9, 2.6.3
wireshark (Red Hat package) - update to 1.10.14-24.el7
wireshark (Alpine package) - addressed in versions 2.4.9-r0, 2.6.3-r0
wireshark - addressed in versions 2.6.4-1.fc28, 2.6.4-1.fc29

External References

Related Security Bulletins