CVE-2018-18227: Null Pointer Dereference
Published Oct 12, 2018
·Updated
In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/dissectors/packet-mswsp.c by properly handling NULL return values.
Affected Software
4 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=2.4.0<=2.4.9
Wireshark Wireshark>=2.6.0<=2.6.3
Debian Debian Linux=9.0
Remediation
Patch Available
Patch Available
Event History
Oct 12, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18227?
CVE-2018-18227 has a medium severity rating due to the potential for the Wireshark application to crash.
2
How do I fix CVE-2018-18227?
To fix CVE-2018-18227, upgrade to Wireshark versions 2.6.4 or later, 2.4.10 or later, or any other version that includes the security patch.
3
What versions of Wireshark are vulnerable to CVE-2018-18227?
Wireshark versions 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9 are vulnerable to CVE-2018-18227.
4
What is the cause of the vulnerability in CVE-2018-18227?
The vulnerability in CVE-2018-18227 is caused by improper handling of NULL return values in the MS-WSP protocol dissector.
5
Does CVE-2018-18227 affect Debian Linux systems?
Yes, CVE-2018-18227 affects Debian Linux systems running vulnerable versions of Wireshark.