CVE-2018-9262: Input Validation
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/packet-vlan.c by limiting VLAN tag nesting to restrict the recursion depth.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wiresharkto a version that resolves this vulnerability.Fixed in 2.4.5 - Upgrade
Upgrade
wiresharkto a version that resolves this vulnerability.Fixed in 2.2.13 - Configuration
Update/apply the fix in epan/dissectors/packet-vlan.c that limits VLAN tag nesting to restrict VLAN dissector recursion depth, preventing crashes in the affected versions (2.4.0–2.4.5 and 2.2.0–2.2.13).
Wireshark VLAN dissector (epan/dissectors/packet-vlan.c) VLAN tag nesting limit = limit VLAN tag nesting to restrict recursion depth
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9262?
CVE-2018-9262 has been classified with a medium severity impact due to the potential for application crashes.
How do I fix CVE-2018-9262?
To address CVE-2018-9262, update Wireshark to version 2.4.6 or later, or apply the relevant patches provided by your operating system.
What are the affected versions for CVE-2018-9262?
CVE-2018-9262 affects Wireshark versions from 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13.
What type of issue is CVE-2018-9262?
CVE-2018-9262 is a vulnerability in the VLAN dissector that could lead to crashes in the Wireshark application.
Who is impacted by CVE-2018-9262?
Users of Wireshark versions 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13 are at risk of experiencing crashes due to CVE-2018-9262.