Wireshark Multiple Denial of Service Vulnerabilities
BID:103158
CVE-2018-7321 | CVE-2018-7322 | CVE-2018-7323 | CVE-2018-7324 | CVE-2018-7325 | CVE-2018-7326 | CVE-2018-7327 | CVE-2018-7328 | CVE-2018-7329 | CVE-2018-7330 | CVE-2018-7331 | CVE-2018-7332 | CVE-2018-7333 |Info
Wireshark Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 103158 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-7321 CVE-2018-7322 CVE-2018-7323 CVE-2018-7324 CVE-2018-7325 CVE-2018-7326 CVE-2018-7327 CVE-2018-7328 CVE-2018-7329 CVE-2018-7330 CVE-2018-7331 CVE-2018-7332 CVE-2018-7333 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2018 12:00AM |
| Updated: | Feb 23 2018 12:00AM |
| Credit: | Jakub Zawadzki |
| Vulnerable: |
Wireshark Wireshark 2.4.4 Wireshark Wireshark 2.4.3 Wireshark Wireshark 2.4.1 Wireshark Wireshark 2.4 Wireshark Wireshark 2.2.12 Wireshark Wireshark 2.2.11 Wireshark Wireshark 2.2.10 Wireshark Wireshark 2.2.9 Wireshark Wireshark 2.2.8 Wireshark Wireshark 2.2.7 Wireshark Wireshark 2.2.6 Wireshark Wireshark 2.2.5 Wireshark Wireshark 2.2.4 Wireshark Wireshark 2.2.3 Wireshark Wireshark 2.2.2 Wireshark Wireshark 2.2.1 Wireshark Wireshark 2.2 Wireshark Wireshark 2.4.2 |
| Not Vulnerable: |
Wireshark Wireshark 2.4.5 Wireshark Wireshark 2.2.13 |
Discussion
Wireshark Multiple Denial of Service Vulnerabilities
Wireshark is prone to multiple denial-of-service vulnerabilities.
An attacker can exploit these issues by injecting a malformed packet onto the wire or by convincing someone to read a malformed pcap file.
Attackers can exploit these issues to cause the application to enter an infinite loop consuming excessive CPU resources, denying service to legitimate users.
Wireshark 2.4.0 through 2.4.4, and 2.2.0 through 2.2.12 are vulnerable.
Wireshark is prone to multiple denial-of-service vulnerabilities.
An attacker can exploit these issues by injecting a malformed packet onto the wire or by convincing someone to read a malformed pcap file.
Attackers can exploit these issues to cause the application to enter an infinite loop consuming excessive CPU resources, denying service to legitimate users.
Wireshark 2.4.0 through 2.4.4, and 2.2.0 through 2.2.12 are vulnerable.
Exploit / POC
Wireshark Multiple Denial of Service Vulnerabilities
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
Solution / Fix
Wireshark Multiple Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Wireshark Multiple Denial of Service Vulnerabilities
References:
References:
- Wireshark Homepage (Wireshark)
- Bug 14379 - [oss-fuzz] thrift long dissector loop (dissect_thrift_map) (Wireshark)
- Bug 14408 - [oss-fuzz] dmp long dissector loop (dissect_dmp_security_category) (Wireshark)
- Bug 14411 - [oss-fuzz] DICOM: inifinite loop (dissect_dcm_tag) (Wireshark)
- Bug 14412 - [oss-fuzz] WCCP: very long loop (Wireshark)
- Bug 14413 - [oss-fuzz] SCCP: infinite loop (dissect_sccp_optional_parameters) (Wireshark)
- Bug 14414 - [oss-fuzz] RPKI-Router Protocol: infinite loop (dissect_rpkirtr_pdu) (Wireshark)
- Bug 14419 - [oss-fuzz] LLTD: infinite loop (dissect_lltd_tlv) (Wireshark)
- Bug 14420 - [oss-fuzz] openflow_v6: infinite loop (Wireshark)
- Bug 14421 - [oss-fuzz] USB-DARWIN: long loop (dissect_darwin_usb_iso_transfer) (Wireshark)
- Bug 14423 - [oss-fuzz] S7COMM: infinite loop (s7comm_decode_ud_cpu_alarm_main) (Wireshark)
- Bug 14428 - [oss-fuzz] #6296 thread_meshcop: infinite loop (get_chancount) (Wireshark)
- Bug 14444 - [oss-fuzz] GTP: infinite loop (Wireshark)
- Bug 14445 - [oss-fuzz] RELOAD: infinite loop (dissect_statans) (Wireshark)
- Bug 14449 - [oss-fuzz] #6467 RPCoRDMA: infinite loop (Wireshark)
- wnpa-sec-2018-06 · Large or infinite loops in multiple dissectors (Wireshark)