CVE-2018-14367: High severity wireshark vulnerability
In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the CoAP protocol dissector could crash. This was addressed in epan/dissectors/packet-coap.c by properly checking for a NULL condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14367?
CVE-2018-14367 has a medium severity rating due to the potential for crashing the application.
How do I fix CVE-2018-14367?
To fix CVE-2018-14367, upgrade Wireshark to version 2.4.8 or later for the 2.4.x branch or 2.6.2 or later for the 2.6.x branch.
What are the affected versions of Wireshark for CVE-2018-14367?
The affected versions of Wireshark for CVE-2018-14367 range from 2.4.0 to 2.4.7 and 2.6.0 to 2.6.1.
What does CVE-2018-14367 exploit?
CVE-2018-14367 exploits a flaw in the CoAP protocol dissector that could lead to application crashes.
Is CVE-2018-14367 related to other vulnerabilities?
While CVE-2018-14367 is specific to certain Wireshark versions, it highlights general security concerns related to improper handling of protocol dissectors.