CVE-2018-14368

HIGH

Wireshark <2.6.1, <2.4.7, <2.2.15 - DoS

Title source: llm
STIX 2.1

Description

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the Bazaar protocol dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by properly handling items that are too long.

References (7)

Core 7
Core References
Vendor Advisory x_refsource_confirm
https://www.wireshark.org/security/wnpa-sec-2018-40.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041608
Exploit, Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14841
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/07/msg00045.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104847

Scores

CVSS v3 7.5
EPSS 0.0135
EPSS Percentile 80.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-835
Status published
Products (2)
debian/debian_linux 8.0
wireshark/wireshark 2.2.0 - 2.2.15
Published Jul 19, 2018
Tracked Since Feb 18, 2026