Wireshark ixw.wave file parser DoS Vulnerability (CVE-2018-5334)
Wireshark ixw.wave file parser DoS Vulnerability (CVE-2018-5334)
Release date:
Updated on:
Affected Systems:
Wireshark 2.4.0-2.4.3
Wireshark 2.2.0-2.2.11
Description:
Bugtraq id: 102499
CVE (CAN) ID: CVE-2018-5334
Wireshark is the most popular network protocol parser.
Wireshark 2.4.0-2.4.3 and 2.2.0-2.2.11 versions have the signature timestamp boundary check vulnerability in wiretap/vwr. c implementation. After successful exploitation, the ixw.wave file parser crashes.
<* Source: Young
*>
Suggestion:
Vendor patch:
Wireshark
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://code.wireshark.org/review/gitweb? P = wireshark. git; a = commit; h = dc308c05ba0673460fe80873b22d296880ee996d
Http://www.wireshark.org/
Https://www.wireshark.org/security/wnpa-sec-2018-03.html
Install the network traffic analysis tool Wireshark in Ubuntu 16.04
Install Wireshark 2.4.3 through PPA in Ubuntu 17.10