CVE-2018-7335: High severity Wireshark Wireshark vulnerability
Published Feb 23, 2018
·Updated
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the IEEE 802.11 dissector could crash. This was addressed in epan/crypt/airpdcap.c by rejecting lengths that are too small.
Affected Software
6 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=2.2.0<=2.2.12
Wireshark Wireshark>=2.4.0<=2.4.4
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/wiresharkto a version that resolves this vulnerability.Fixed in 2.6.20-0+deb10u4Fixed in 2.6.20-0+deb10u7Fixed in 3.4.10-0+deb11u1Fixed in 4.0.6-1~deb12u1Fixed in 4.0.10-1
Event History
Feb 23, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7335?
CVE-2018-7335 has a medium severity due to the potential for crashing the Wireshark application.
2
How do I fix CVE-2018-7335?
To fix CVE-2018-7335, upgrade Wireshark to version 2.4.5 or later, or to any of the mentioned fixed versions.
3
Which versions of Wireshark are affected by CVE-2018-7335?
Wireshark versions 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12 are affected by CVE-2018-7335.
4
What component of Wireshark does CVE-2018-7335 impact?
CVE-2018-7335 impacts the IEEE 802.11 dissector in Wireshark.
5
Is CVE-2018-7335 specific to any operating system?
CVE-2018-7335 is primarily a concern for Wireshark running on Debian systems.