CVE-2014-2299

Wireshark <1.8.13, <1.10.6 - Buffer Overflow

Title source: llm

Description

Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/33069
metasploit WORKING POC GOOD
by Wesley Neelen, j0sm1 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/wireshark_mpeg_overflow.rb

Scores

EPSS 0.6796
EPSS Percentile 98.6%

Details

CWE
CWE-119
Status published
Products (19)
wireshark/wireshark 1.8.0
wireshark/wireshark 1.8.1
wireshark/wireshark 1.8.2
wireshark/wireshark 1.8.3
wireshark/wireshark 1.8.4
wireshark/wireshark 1.8.5
wireshark/wireshark 1.8.6
wireshark/wireshark 1.8.7
wireshark/wireshark 1.8.8
wireshark/wireshark 1.8.9
... and 9 more
Published Mar 11, 2014
Tracked Since Feb 18, 2026