CVE-2014-2281: Input Validation
The nfsnamesnoopaddname function in epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 does not validate a certain length value, which allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted NFS packet.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2281?
CVE-2014-2281 is classified as a medium severity vulnerability that can lead to denial of service via application crash.
How do I fix CVE-2014-2281?
To fix CVE-2014-2281, upgrade to Wireshark version 1.8.13 or 1.10.6 or later.
What types of attacks does CVE-2014-2281 enable?
CVE-2014-2281 can enable remote attackers to cause memory corruption and crash the Wireshark application.
Which versions of Wireshark are affected by CVE-2014-2281?
Wireshark versions 1.8.x before 1.8.13 and 1.10.x before 1.10.6 are affected by CVE-2014-2281.
What component of Wireshark does CVE-2014-2281 affect?
CVE-2014-2281 affects the NFS dissector component in Wireshark.