CVE-2018-14938: Integer Overflow
An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handleprism during caplen processing. If the caplen is less than 144, one can cause an integer overflow in the function handle80211, which will result in an out-of-bounds read and may allow access to sensitive memory (or a denial of service).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14938?
CVE-2018-14938 has been classified as a high severity vulnerability due to the potential for an integer overflow leading to out-of-bounds reads.
How do I fix CVE-2018-14938?
To fix CVE-2018-14938, update tcpflow to version 1.5.2+repack1-1 or later on Debian, or to version 1.4.5+ or later on Ubuntu.
Which versions of tcpflow are affected by CVE-2018-14938?
Affected versions of tcpflow include 1.5.0-alpha and earlier versions up to 1.4.5.
Is my system at risk if I use tcpflow version 1.5.0-alpha regarding CVE-2018-14938?
Yes, using tcpflow version 1.5.0-alpha puts your system at risk due to the integer overflow vulnerability described in CVE-2018-14938.
What software sources include tcpflow vulnerable to CVE-2018-14938?
CVE-2018-14938 affects tcpflow versions found in Debian and Ubuntu distributions, particularly versions below 1.5.2 on Debian and below 1.4.5 on Ubuntu.