CVE-2018-9273: High severity Wireshark Wireshark vulnerability
Published Apr 4, 2018
·Updated
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-pcp.c has a memory leak.
Affected Software
5 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=2.2.0<=2.2.13
Wireshark Wireshark>=2.4.0<=2.4.5
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/wiresharkto a version that resolves this vulnerability.Fixed in 2.6.20-0+deb10u4Fixed in 2.6.20-0+deb10u7Fixed in 3.4.10-0+deb11u1Fixed in 4.0.6-1~deb12u1Fixed in 4.0.10-1
Event History
Apr 4, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Data Sourced
via NVD·07:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9273?
CVE-2018-9273 has a low severity rating due to its nature as a memory leak in Wireshark.
2
How do I fix CVE-2018-9273?
To fix CVE-2018-9273, you should upgrade Wireshark to version 2.4.6 or later.
3
Which versions of Wireshark are affected by CVE-2018-9273?
CVE-2018-9273 affects Wireshark versions from 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13.
4
Is CVE-2018-9273 applicable only to Wireshark?
CVE-2018-9273 primarily affects Wireshark but is also relevant for users of Debian GNU/Linux versions 8.0 and 9.0.
5
What type of vulnerability is CVE-2018-9273?
CVE-2018-9273 is classified as a memory leak vulnerability.