CVE-2018-7337: High severity Wireshark Wireshark vulnerability
In Wireshark 2.4.0 to 2.4.4, the DOCSIS protocol dissector could crash. This was addressed in plugins/docsis/packet-docsis.c by removing the recursive algorithm that had been used for concatenated PDUs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wireshark/plugins/docsis (packet-docsis.c)to a version that resolves this vulnerability.Fixed in 2.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7337?
CVE-2018-7337 is classified as a medium-severity vulnerability due to its potential to cause crashes in Wireshark.
How do I fix CVE-2018-7337?
To fix CVE-2018-7337, update Wireshark to version 2.4.5 or later, which addresses the recursive algorithm issue.
What versions of Wireshark are affected by CVE-2018-7337?
CVE-2018-7337 affects Wireshark versions 2.4.0 to 2.4.4.
Can CVE-2018-7337 impact network analysis in Wireshark?
Yes, CVE-2018-7337 can impact network analysis by causing the application to crash during the processing of DOCSIS protocols.
Is CVE-2018-7337 relevant for Debian Linux users?
Yes, CVE-2018-7337 is relevant for Debian users running version 7.0 with the affected version of Wireshark installed.