CVE-2018-11360: Buffer Overflow
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epan/dissectors/packet-gsmadtap.c by fixing an off-by-one error that caused a buffer overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11360?
CVE-2018-11360 is classified as a high severity vulnerability due to the potential for crash and denial of service.
How do I fix CVE-2018-11360?
You can mitigate CVE-2018-11360 by upgrading Wireshark to a patched version such as 2.6.20 or later.
Which versions of Wireshark are affected by CVE-2018-11360?
CVE-2018-11360 affects versions of Wireshark from 2.2.0 to 2.2.14, from 2.4.0 to 2.4.6, and specifically 2.6.0.
What specific error was addressed in CVE-2018-11360?
CVE-2018-11360 was addressed by fixing an off-by-one error that caused a buffer overflow in the GSM A DTAP dissector.
Is CVE-2018-11360 related to any specific operating systems?
CVE-2018-11360 impacts Wireshark installations on various Debian Linux distributions including Debian 8 and 9.