PT-2018-12468 · Wireshark+4 · Wireshark+4

Published

2018-04-03

·

Updated

2024-06-15

·

CVE-2018-14368

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wireshark versions 2.2.0 through 2.2.15 Wireshark versions 2.4.0 through 2.4.7 Wireshark versions 2.6.0 through 2.6.1
Description The Bazaar protocol dissector in Wireshark could enter an infinite loop due to improper handling of items that are too long. This issue was addressed by properly handling such items in the epan/dissectors/packet-bzr.c file.
Recommendations For Wireshark versions 2.2.0 through 2.2.15, update the epan/dissectors/packet-bzr.c file to properly handle items that are too long. For Wireshark versions 2.4.0 through 2.4.7, update the epan/dissectors/packet-bzr.c file to properly handle items that are too long. For Wireshark versions 2.6.0 through 2.6.1, update the epan/dissectors/packet-bzr.c file to properly handle items that are too long.

Exploit

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1549
ALT-PU-2018-2048
ALT-PU-2018-2487
CESA-2020_1047
CVE-2018-14368
DLA-1451-1
MGASA-2018-0320
OPENSUSE-SU-2018_2184-1
OPENSUSE-SU-2018_2188-1
OPENSUSE-SU-2020:0362-1
OPENSUSE-SU-2020_0362-1
OPENSUSE-SU-2024:11513-1
RHSA-2020:1047
RHSA-2020_1047
SUSE-SU-2018:2301-1
SUSE-SU-2018:2412-1
SUSE-SU-2018:2891-1
SUSE-SU-2018:2891-2
SUSE-SU-2020:0693-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Wireshark