CVE-2018-11362: High severity wireshark vulnerability
Published May 22, 2018
·Updated
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by avoiding a buffer over-read upon encountering a missing '\0' character.
Affected Software
7 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=2.2.0<=2.2.14
Wireshark Wireshark>=2.4.0<=2.4.6
Wireshark Wireshark=2.6.0
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Event History
May 22, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11362?
CVE-2018-11362 is classified as a vulnerability that can lead to a crash in certain versions of Wireshark.
2
How do I fix CVE-2018-11362?
To mitigate CVE-2018-11362, upgrade to Wireshark versions 2.6.20 or later, or 3.4.10 or later.
3
Which versions of Wireshark are affected by CVE-2018-11362?
CVE-2018-11362 affects Wireshark versions 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14.
4
What component in Wireshark is vulnerable in CVE-2018-11362?
The LDSS dissector in Wireshark is the component that has the vulnerability in CVE-2018-11362.
5
Is CVE-2018-11362 specific to certain operating systems?
CVE-2018-11362 affects the Wireshark application regardless of the operating system as long as the specified vulnerable versions are used.