CVE-2018-14343

Name
CVE-2018-14343
Description
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash. This was addressed in epan/dissectors/packet-ber.c by ensuring that length values do not exceed the maximum signed integer.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Vendor Advisory https://www.wireshark.org/security/wnpa-sec-2018-37.html
Patch https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=9402f2f80c6bc7d25178a0875c5a1f5ee36361db
Issue Tracking https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14682
Third Party Advisory http://www.securityfocus.com/bid/104847
Mailing List https://lists.debian.org/debian-lts-announce/2018/07/msg00045.html
Third Party Advisory http://www.securitytracker.com/id/1041608
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* wireshark >= 2.2.0 <= 2.2.15
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* wireshark >= 2.4.0 <= 2.4.7
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* wireshark >= 2.6.0 <= 2.6.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status