CVE-2014-4020: Medium severity Wireshark Wireshark vulnerability
Published Jun 18, 2014
·Updated
The dissectframe function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even though it was intended to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Affected Software
8 affected components
Wireshark Wireshark=1.10.0
Wireshark Wireshark=1.10.1
Wireshark Wireshark=1.10.2
Wireshark Wireshark=1.10.3
Wireshark Wireshark=1.10.4
Wireshark Wireshark=1.10.5
Wireshark Wireshark=1.10.6
Wireshark Wireshark=1.10.7
Remediation
Event History
Jun 18, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4020?
CVE-2014-4020 is categorized as a denial of service vulnerability.
2
How do I fix CVE-2014-4020?
To mitigate CVE-2014-4020, upgrade Wireshark to version 1.10.8 or later.
3
Which versions of Wireshark are affected by CVE-2014-4020?
CVE-2014-4020 affects Wireshark versions 1.10.0 through 1.10.7.
4
What types of problems does CVE-2014-4020 cause?
CVE-2014-4020 allows remote attackers to trigger a denial of service through manipulating length values.
5
Who is primarily affected by CVE-2014-4020?
Users of Wireshark versions 1.10.x prior to 1.10.8 are primarily impacted by CVE-2014-4020.