Wireshark CVE-2018-5336 Multiple Denial of Service Vulnerabilities
BID:102504
CVE-2018-5336 |Info
Wireshark CVE-2018-5336 Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 102504 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-5336 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2018 12:00AM |
| Updated: | Jan 11 2018 12:00AM |
| Credit: | Kamil Frankowicz |
| Vulnerable: |
Wireshark Wireshark 2.4.3 Wireshark Wireshark 2.4.1 Wireshark Wireshark 2.4 Wireshark Wireshark 2.2.11 Wireshark Wireshark 2.2.10 Wireshark Wireshark 2.2.9 Wireshark Wireshark 2.2.8 Wireshark Wireshark 2.2.7 Wireshark Wireshark 2.2.6 Wireshark Wireshark 2.2.5 Wireshark Wireshark 2.2.4 Wireshark Wireshark 2.2.3 Wireshark Wireshark 2.2.2 Wireshark Wireshark 2.2.1 Wireshark Wireshark 2.2 Wireshark Wireshark 2.4.2 Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 |
| Not Vulnerable: |
Wireshark Wireshark 2.4.4 Wireshark Wireshark 2.2.12 |
Discussion
Wireshark CVE-2018-5336 Multiple Denial of Service Vulnerabilities
Wireshark is prone to multiple denial-of-service vulnerabilities.
An attacker can leverage these issues to crash the affected application, denying service to legitimate users.
Wireshark versions 2.4.0 through 2.4.3, and 2.2.0 through 2.2.11 are vulnerable.
Wireshark is prone to multiple denial-of-service vulnerabilities.
An attacker can leverage these issues to crash the affected application, denying service to legitimate users.
Wireshark versions 2.4.0 through 2.4.3, and 2.2.0 through 2.2.11 are vulnerable.
Exploit / POC
Wireshark CVE-2018-5336 Multiple Denial of Service Vulnerabilities
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
Solution / Fix
Wireshark CVE-2018-5336 Multiple Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Wireshark CVE-2018-5336 Multiple Denial of Service Vulnerabilities
References:
References:
- Bug 14253 - Stack overflow in cond_some() (Wireshark)
- Bug 1534374 - (CVE-2018-5336) CVE-2018-5336 wireshark: Missing recursion limit i (Red Hat Bugzilla)
- CVE-2018-5336 (Red Hat Bugzilla)
- Wireshark Homepage (Wireshark)
- wnpa-sec-2018-01 · Multiple dissectors could crash (Wireshark)