CVE-2018-7321: High severity Wireshark Wireshark vulnerability
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with dissection after encountering an unexpected type.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7321?
CVE-2018-7321 has been classified as a medium severity vulnerability due to its potential for denial-of-service attacks.
How do I fix CVE-2018-7321?
To resolve CVE-2018-7321, upgrade Wireshark to version 2.4.5 or later for the 2.4.x series and to version 2.2.13 or later for the 2.2.x series.
What impact does CVE-2018-7321 have on affected systems?
CVE-2018-7321 can cause Wireshark to enter a large loop, potentially leading to performance degradation or crashes.
Is CVE-2018-7321 present in all versions of Wireshark?
No, CVE-2018-7321 affects only Wireshark versions 2.4.0 through 2.4.4 and 2.2.0 through 2.2.12.
How can I determine if I am vulnerable to CVE-2018-7321?
Check your Wireshark version and determine if it's between the affected ranges to see if you're vulnerable to CVE-2018-7321.