CVE-2018-14344: High severity wireshark vulnerability
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ISMP dissector could crash. This was addressed in epan/dissectors/packet-ismp.c by validating the IPX address length to avoid a buffer over-read.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14344?
CVE-2018-14344 is classified as a high severity vulnerability due to its potential to crash the Wireshark application.
How do I fix CVE-2018-14344?
To fix CVE-2018-14344, upgrade to Wireshark version 2.6.2 or later, 2.4.8 or later, or 2.2.16 or later.
What versions of Wireshark are affected by CVE-2018-14344?
CVE-2018-14344 affects Wireshark versions 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15.
What type of attack does CVE-2018-14344 facilitate?
CVE-2018-14344 could allow an attacker to crash the Wireshark application through malformed ISMP packets.
Is CVE-2018-14344 a remote or local vulnerability?
CVE-2018-14344 is considered a remote vulnerability because it can be exploited by sending specially crafted packets to the Wireshark application.