Wireshark fixed three flaws that can crash it via malicious packet trace files
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-16057 | In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed in epan/dissectors/packet-ieee80211-radiotap-iter.c by validating iterator operations. NVD description · AI analysis pending | 7.5 | 3% |
| — |
Full article124 words · extracted from securityaffairs.com · click to collapse
“To exploit the vulnerability, the attacker may use misleading language and instructions to convince a user to open a malicious packet trace file.” reads the security advisory published for the CVE-2018-16057 flaw.
“To inject malformed packets that the Wireshark application may attempt to parse, the attacker may need access to the trusted, internal network where the targeted system resides. This access requirement may reduce the likelihood of a successful exploit.”
Anyway, to trigger the flaw it is necessary to access to a malicious packet trace file, a circumstance that makes the likelihood of exploitation very low.
Wireshark users need to upgrade their install to one of these: 2.6.3, 2.4.9, or 2.2.17.
Below the list of safeguards provided by Cisco in the security advisory:
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/75834/hacking/wireshark-dos-flaws.html