ZeroHour

CVE-2018-14339

CVSS 3.0
7.5 high
EPSS
4%p89
Published
()
Modified
Description

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE dissector could go into an infinite loop. This was addressed in epan/proto.c by adding offset and length validation.

Vendors
wiresharkdebian
Products
wireshark, debian linux
Weakness
CWE-20, CWE-835
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.