PT-2018-2540 · Wireshark+2 · Wireshark+2
Publicado
2018-10-09
·
Atualizado
2024-06-15
·
CVE-2018-18225
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Wireshark versions 2.6.0 through 2.6.3
Description
The issue is related to the CoAP dissector in Wireshark, which could crash due to incorrect computation of the piv length. This could potentially allow a remote attacker to cause a denial of service. The problem is associated with incorrect checking of the volume of submitted data.
Recommendations
For Wireshark versions 2.6.0 through 2.6.3, update the epan/dissectors/packet-coap.c file to ensure the piv length is correctly computed, as addressed in the fix.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Wireshark