First published: Wed Apr 04 2018(Updated: )
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/packet-vlan.c by limiting VLAN tag nesting to restrict the recursion depth.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | >=2.2.0<=2.2.13 | |
Wireshark Wireshark | >=2.4.0<=2.4.5 | |
Debian GNU/Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9262 has been classified with a medium severity impact due to the potential for application crashes.
To address CVE-2018-9262, update Wireshark to version 2.4.6 or later, or apply the relevant patches provided by your operating system.
CVE-2018-9262 affects Wireshark versions from 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13.
CVE-2018-9262 is a vulnerability in the VLAN dissector that could lead to crashes in the Wireshark application.
Users of Wireshark versions 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13 are at risk of experiencing crashes due to CVE-2018-9262.