Wireshark DOCSIS Dissector CVE-2018-7337 Denial of Service Vulnerability
BID:103164
CVE-2018-7337 |Info
Wireshark DOCSIS Dissector CVE-2018-7337 Denial of Service Vulnerability
| Bugtraq ID: | 103164 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-7337 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2018 12:00AM |
| Updated: | Feb 23 2018 12:00AM |
| Credit: | Jakub Zawadzki |
| Vulnerable: |
Wireshark Wireshark 2.4.4 Wireshark Wireshark 2.4.3 Wireshark Wireshark 2.4.1 Wireshark Wireshark 2.4 Wireshark Wireshark 2.4.2 |
| Not Vulnerable: |
Wireshark Wireshark 2.4.5 |
Discussion
Wireshark DOCSIS Dissector CVE-2018-7337 Denial of Service Vulnerability
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark versions 2.4.0 through 2.4.4 are vulnerable.
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark versions 2.4.0 through 2.4.4 are vulnerable.
Exploit / POC
Wireshark DOCSIS Dissector CVE-2018-7337 Denial of Service Vulnerability
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
References
Wireshark DOCSIS Dissector CVE-2018-7337 Denial of Service Vulnerability
References:
References:
- Wireshark Homepage (Wireshark)
- Bug 14446 - [oss-fuzz] #6458 DOCSIS: Stack-overflow in dissect_docsis (Wireshark)
- wnpa-sec-2018-08 · DOCSIS dissector crash (Wireshark)