CVE-2018-9259: Input Validation
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the box recursion depth.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update Wireshark to the release that includes the fix in epan/dissectors/file-mp4.c by restricting the MP4 dissector box recursion depth to prevent crashes in versions 2.4.0–2.4.5 and 2.2.0–2.2.13.
Wireshark (epan/dissectors/file-mp4.c MP4 dissector) MP4 dissector box recursion depth = restricted (set lower maximum)
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9259?
CVE-2018-9259 is classified as a medium severity vulnerability due to potential application crashes.
How do I fix CVE-2018-9259?
To fix CVE-2018-9259, update Wireshark to version 2.4.6 or later for 2.4.x series and version 2.2.14 or later for 2.2.x series.
Which versions of Wireshark are affected by CVE-2018-9259?
CVE-2018-9259 affects Wireshark versions 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13.
What components of Wireshark does CVE-2018-9259 impact?
CVE-2018-9259 impacts the MP4 dissector component of Wireshark.
Is there a workaround for CVE-2018-9259?
There is no known workaround for CVE-2018-9259 other than applying the timely software updates.