CVE-2018-11359: Null Pointer Dereference
Published May 22, 2018
·Updated
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash. This was addressed in epan/proto.c by avoiding a NULL pointer dereference.
Affected Software
4 affected components
Wireshark Wireshark>=2.2.0<=2.2.14
Wireshark Wireshark>=2.4.0<=2.4.6
Wireshark Wireshark=2.6.0
Debian Debian Linux=8.0
Remediation
Event History
May 22, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11359?
CVE-2018-11359 is classified as medium severity due to the potential for crashes in affected Wireshark versions.
2
How do I fix CVE-2018-11359?
To fix CVE-2018-11359, you should upgrade to Wireshark version 2.6.1 or later, or ensure you're running a secure version of Wireshark.
3
What versions are affected by CVE-2018-11359?
CVE-2018-11359 affects Wireshark versions 2.2.0 to 2.2.14, 2.4.0 to 2.4.6, and 2.6.0.
4
What is the impact of CVE-2018-11359?
The impact of CVE-2018-11359 is that it can lead to crashes in the application when using the affected versions.
5
Is CVE-2018-11359 still a risk if I have updated my software?
No, CVE-2018-11359 is no longer a risk if you have updated to a patched version of Wireshark.