CVE-2014-2283: Use After Free
epan/dissectors/packet-rlc in the RLC dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 uses inconsistent memory-management approaches, which allows remote attackers to cause a denial of service (use-after-free error and application crash) via a crafted UMTS Radio Link Control packet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2283?
CVE-2014-2283 has a severity rating that indicates it can lead to a denial of service due to a use-after-free vulnerability.
What software versions are affected by CVE-2014-2283?
CVE-2014-2283 affects Wireshark versions 1.8.0 through 1.8.12 and 1.10.0 through 1.10.5.
How do I fix CVE-2014-2283?
To fix CVE-2014-2283, upgrade Wireshark to version 1.8.13 or 1.10.6 or later.
What type of attack does CVE-2014-2283 enable?
CVE-2014-2283 enables remote attackers to crash the application via crafted UMTS Radio Link Control packets.
Is there a workaround for CVE-2014-2283?
There are no known workarounds for CVE-2014-2283; updating to a patched version is necessary.