CVE-2018-9260: Input Validation
Published Apr 4, 2018
·Updated
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dissectors/packet-ieee802154.c by ensuring that an allocation step occurs.
Affected Software
4 affected components
Wireshark Wireshark>=2.2.0<=2.2.13
Wireshark Wireshark>=2.4.0<=2.4.5
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Remediation
Event History
Apr 4, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Data Sourced
via NVD·07:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9260?
CVE-2018-9260 has been classified as a high severity vulnerability.
2
What are the affected versions for CVE-2018-9260?
CVE-2018-9260 affects Wireshark versions 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13.
3
How do I fix CVE-2018-9260?
To fix CVE-2018-9260, upgrade Wireshark to the latest version that addresses the vulnerability.
4
Can CVE-2018-9260 cause any issues while using Wireshark?
Yes, CVE-2018-9260 can cause Wireshark to crash when processing specific IEEE 802.15.4 packets.
5
Is CVE-2018-9260 present in Debian Linux distributions?
Yes, CVE-2018-9260 is present in Debian GNU/Linux versions 7.0 and 8.0.