CVE-2018-9261: Buffer Overflow
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-nbap.c by prohibiting the self-linking of DCH-IDs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/wiresharkto a version that resolves this vulnerability.Fixed in 2.6.20-0+deb10u4Fixed in 2.6.20-0+deb10u7Fixed in 3.4.10-0+deb11u1Fixed in 4.0.6-1~deb12u1Fixed in 4.0.10-1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9261?
CVE-2018-9261 has a moderate severity rating due to the potential for a heap-based buffer overflow that can lead to application crashes.
How do I fix CVE-2018-9261?
To mitigate CVE-2018-9261, update Wireshark to versions 2.6.20 or later, 3.4.10 or later, or 4.0.6 or later.
Which versions of Wireshark are affected by CVE-2018-9261?
Wireshark versions 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13 are affected by CVE-2018-9261.
What component of Wireshark is vulnerable in CVE-2018-9261?
The vulnerability in CVE-2018-9261 affects the NBAP dissector within Wireshark.
Is there a workaround for CVE-2018-9261 if I cannot update immediately?
There is no specific workaround for CVE-2018-9261, so upgrading to a secure version is strongly recommended.