Memory leak in Wireshark - CVE-2018-18226
Published: October 12, 2018
Vulnerability identifier: #VU15335
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-18226
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to memory leak in the Steam IHS Discovery dissector when handling malicious input. A remote attacker can inject a malformed packet into a network, to be processed by the affected application, or trick the victim into opening a malicious packet trace file and gain access to arbitrary data.
Affected software
Wireshark
Arch Linux
Debian Linux
Opensuse
Fedora
wireshark (Alpine package)
wireshark
Arch Linux
Debian Linux
Opensuse
Fedora
wireshark (Alpine package)
wireshark
How to mitigate CVE-2018-18226
The vulnerability has been addressed in the version 2.6.4.
Wireshark - update to 2.6.4
wireshark (Alpine package) - update to 2.4.10-r0
wireshark - addressed in versions 2.6.4-1.fc28, 2.6.4-1.fc29
wireshark (Alpine package) - update to 2.4.10-r0
wireshark - addressed in versions 2.6.4-1.fc28, 2.6.4-1.fc29