CVE-2014-4174: Buffer Overflow
Published Jun 18, 2014
·Updated
wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a large packet.
Affected Software
4 affected components
Wireshark Wireshark=1.10.0
Wireshark Wireshark=1.10.1
Wireshark Wireshark=1.10.2
Wireshark Wireshark=1.10.3
Remediation
Event History
Jun 18, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4174?
CVE-2014-4174 is considered critical as it allows remote attackers to execute arbitrary code or cause a denial of service.
2
How do I fix CVE-2014-4174?
To fix CVE-2014-4174, upgrade Wireshark to version 1.10.4 or later.
3
What versions of Wireshark are affected by CVE-2014-4174?
Wireshark versions 1.10.0 through 1.10.3 are affected by CVE-2014-4174.
4
What type of attacks can CVE-2014-4174 enable?
CVE-2014-4174 can enable remote code execution and memory corruption attacks.
5
Is there a workaround for CVE-2014-4174?
There are no known workarounds for CVE-2014-4174; upgrading Wireshark is the recommended action.