Wireshark IEEE 802.11 Dissector 'epan/crypt/airpdcap.c' Denial of Service Vulnerability
BID:103165
CVE-2018-7335 |Info
Wireshark IEEE 802.11 Dissector 'epan/crypt/airpdcap.c' Denial of Service Vulnerability
| Bugtraq ID: | 103165 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-7335 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2018 12:00AM |
| Updated: | Feb 23 2018 12:00AM |
| Credit: | Jakub Zawadzki |
| Vulnerable: |
Wireshark Wireshark 2.4.4 Wireshark Wireshark 2.4.3 Wireshark Wireshark 2.4.1 Wireshark Wireshark 2.4 Wireshark Wireshark 2.2.12 Wireshark Wireshark 2.2.11 Wireshark Wireshark 2.2.10 Wireshark Wireshark 2.2.9 Wireshark Wireshark 2.2.8 Wireshark Wireshark 2.2.7 Wireshark Wireshark 2.2.6 Wireshark Wireshark 2.2.5 Wireshark Wireshark 2.2.4 Wireshark Wireshark 2.2.3 Wireshark Wireshark 2.2.2 Wireshark Wireshark 2.2.1 Wireshark Wireshark 2.2 Wireshark Wireshark 2.4.2 |
| Not Vulnerable: |
Wireshark Wireshark 2.4.5 Wireshark Wireshark 2.2.13 |
Discussion
Wireshark IEEE 802.11 Dissector 'epan/crypt/airpdcap.c' Denial of Service Vulnerability
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark versions 2.4.0 through 2.4.4 and 2.2.0 through 2.2.12 are vulnerable.
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark versions 2.4.0 through 2.4.4 and 2.2.0 through 2.2.12 are vulnerable.
Exploit / POC
Wireshark IEEE 802.11 Dissector 'epan/crypt/airpdcap.c' Denial of Service Vulnerability
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
Solution / Fix
Wireshark IEEE 802.11 Dissector 'epan/crypt/airpdcap.c' Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Wireshark IEEE 802.11 Dissector 'epan/crypt/airpdcap.c' Denial of Service Vulnerability
References:
References:
- Bug 14442 - [oss-fuzz] #6336 ieee80211: Crash in _gcry_aes_cbc_enc (AirPDcapPack (Wireshark)
- Wireshark Homepage (Wireshark)
- wnpa-sec-2018-05 · IEEE 802.11 dissector crash (Wireshark)