CVE-2018-7331: High severity Wireshark Wireshark vulnerability
Published Feb 23, 2018
·Updated
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-ber.c had an infinite loop that was addressed by validating a length.
Affected Software
3 affected components
Wireshark Wireshark>=2.2.0<=2.2.12
Wireshark Wireshark>=2.4.0<=2.4.4
Debian Debian Linux=8.0
Remediation
Event History
Feb 23, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7331?
CVE-2018-7331 is classified as a medium severity vulnerability due to its potential to cause an infinite loop in the Wireshark application.
2
How do I fix CVE-2018-7331?
To fix CVE-2018-7331, update Wireshark to version 2.4.5 or 2.2.13 or later, where the issue has been addressed.
3
Which versions of Wireshark are affected by CVE-2018-7331?
CVE-2018-7331 affects Wireshark versions 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12.
4
Does CVE-2018-7331 affect Debian users?
Yes, CVE-2018-7331 can affect Debian GNU/Linux 8.0 users running the vulnerable versions of Wireshark.
5
What type of vulnerability is CVE-2018-7331?
CVE-2018-7331 is a denial of service vulnerability that occurs due to an infinite loop caused by improper validation of packet length.