First published: Fri Jul 20 2018(Updated: )
In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | <=2.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14438 is considered to have a high severity due to its potential for unauthorized access control modifications.
To fix CVE-2018-14438, you should update Wireshark to a version later than 2.6.2 that addresses this vulnerability.
CVE-2018-14438 affects Wireshark versions up to and including 2.6.2.
The risks related to CVE-2018-14438 include the potential for attackers to arbitrarily modify access controls.
Yes, CVE-2018-14438 is related to the create_app_running_mutex function in the wsutil/file_util.c file.