CVE-2018-14341: Integer Overflow
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM dissector could go into a large or infinite loop. This was addressed in epan/dissectors/packet-dcm.c by preventing an offset overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14341?
CVE-2018-14341 has a medium severity rating as it may lead to a denial of service due to an infinite loop.
How do I fix CVE-2018-14341?
To fix CVE-2018-14341, upgrade Wireshark to the latest version that is not affected, specifically versions later than 2.6.1, 2.4.7, or 2.2.15.
Which versions of Wireshark are vulnerable to CVE-2018-14341?
Wireshark versions 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15 are vulnerable to CVE-2018-14341.
Does CVE-2018-14341 affect Debian Linux?
Yes, CVE-2018-14341 affects the Debian Linux 8.0 distribution if it includes vulnerable versions of Wireshark.
What is the nature of the vulnerability described in CVE-2018-14341?
CVE-2018-14341 involves a large or infinite loop in the DICOM dissector, which can result in denial of service.