CVE-2018-5334: Buffer Overflow
In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/wiresharkto a version that resolves this vulnerability.Fixed in 2.6.20-0+deb10u4Fixed in 2.6.20-0+deb10u7Fixed in 3.4.10-0+deb11u1Fixed in 4.0.6-1~deb12u1Fixed in 4.0.10-1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5334?
CVE-2018-5334 has a moderate severity rating due to the potential for application crashes when parsing IxVeriWave files in vulnerable versions of Wireshark.
How do I fix CVE-2018-5334?
To fix CVE-2018-5334, upgrade Wireshark to version 2.6.20-0+deb10u4 or later, 2.4.3 or later, or any supported version if using Debian.
Which versions of Wireshark are affected by CVE-2018-5334?
CVE-2018-5334 affects Wireshark versions from 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11.
Is CVE-2018-5334 related to any specific operating system?
CVE-2018-5334 impacts Wireshark installations across multiple Debian Linux distributions including versions 7.0, 8.0, and 9.0.
What is the nature of the issue in CVE-2018-5334?
CVE-2018-5334 is a vulnerability in the IxVeriWave file parser that can cause a crash in the application.