CVE-2014-2299: Buffer Overflow
Published Mar 11, 2014
·Updated
Buffer overflow in the mpegread function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.
Affected Software
19 affected components
Wireshark Wireshark=1.8.0
Wireshark Wireshark=1.8.1
Wireshark Wireshark=1.8.2
Wireshark Wireshark=1.8.3
Wireshark Wireshark=1.8.4
Wireshark Wireshark=1.8.5
Wireshark Wireshark=1.8.6
Wireshark Wireshark=1.8.7
Wireshark Wireshark=1.8.8
Wireshark Wireshark=1.8.9
Wireshark Wireshark=1.8.10
Wireshark Wireshark=1.8.11
Wireshark Wireshark=1.8.12
Wireshark Wireshark=1.10.0
Wireshark Wireshark=1.10.1
Wireshark Wireshark=1.10.2
Wireshark Wireshark=1.10.3
Wireshark Wireshark=1.10.4
Wireshark Wireshark=1.10.5
Remediation
Event History
Mar 11, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:01 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2299?
CVE-2014-2299 is considered critical due to its potential to allow remote code execution or application crashes.
2
How do I fix CVE-2014-2299?
To fix CVE-2014-2299, upgrade Wireshark to version 1.8.13 or 1.10.6 or later.
3
What versions of Wireshark are affected by CVE-2014-2299?
CVE-2014-2299 affects Wireshark versions 1.8.x prior to 1.8.13 and 1.10.x prior to 1.10.6.
4
Can CVE-2014-2299 lead to denial of service?
Yes, CVE-2014-2299 can cause a denial of service by crashing the application.
5
What functions are involved in the vulnerability CVE-2014-2299?
CVE-2014-2299 involves a buffer overflow in the 'mpeg_read' function within the MPEG parser.