First published: Fri Feb 23 2018(Updated: )
In Wireshark 2.4.0 to 2.4.4, the DOCSIS protocol dissector could crash. This was addressed in plugins/docsis/packet-docsis.c by removing the recursive algorithm that had been used for concatenated PDUs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | >=2.4.0<=2.4.4 | |
Debian GNU/Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7337 is classified as a medium-severity vulnerability due to its potential to cause crashes in Wireshark.
To fix CVE-2018-7337, update Wireshark to version 2.4.5 or later, which addresses the recursive algorithm issue.
CVE-2018-7337 affects Wireshark versions 2.4.0 to 2.4.4.
Yes, CVE-2018-7337 can impact network analysis by causing the application to crash during the processing of DOCSIS protocols.
Yes, CVE-2018-7337 is relevant for Debian users running version 7.0 with the affected version of Wireshark installed.