CVE-2018-18225: High severity wireshark vulnerability
Published Oct 12, 2018
·Updated
In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.
Affected Software
4 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=2.6.0<=2.6.3
Debian Debian Linux=9.0
openSUSE Leap=15.1
Remediation
Patch Available
Event History
Oct 12, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18225?
CVE-2018-18225 has a medium severity rating due to its potential to cause application crashes.
2
How do I fix CVE-2018-18225?
To fix CVE-2018-18225, update Wireshark to version 2.6.20 or later.
3
Which versions of Wireshark are affected by CVE-2018-18225?
Wireshark versions 2.6.0 to 2.6.3 are affected by CVE-2018-18225.
4
What component of Wireshark is vulnerable in CVE-2018-18225?
The CoAP dissector component of Wireshark is vulnerable in CVE-2018-18225.
5
Is there a known workaround for CVE-2018-18225?
There is no known workaround for CVE-2018-18225 other than upgrading to a fixed version of Wireshark.