PT-2018-16903 · Wireshark+2 · Wireshark+2

Kamil Frankowicz

+1

·

Published

2018-01-11

·

Updated

2024-06-15

·

CVE-2018-5335

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wireshark versions 2.2.0 through 2.2.11 Wireshark versions 2.4.0 through 2.4.3
Description The issue concerns a potential crash in the WCP dissector due to insufficient validation of the available buffer length. This was resolved by implementing proper validation in the dissector code.
Recommendations For Wireshark versions 2.2.0 through 2.2.11, update to a version that includes the fix for the WCP dissector crash. For Wireshark versions 2.4.0 through 2.4.3, update to a version that includes the fix for the WCP dissector crash.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1050
ALT-PU-2018-2487
CVE-2018-5335
DLA-1258-1
DSA-4101-1
MGASA-2018-0071
OPENSUSE-SU-2024:11513-1
SUSE-SU-2018:0179-1
SUSE-SU-2018:0191-1

Affected Products

Alt Linux
Suse
Wireshark