CVE-2014-4174
published 2014-06-18CVE-2014-4174: wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.93%
92.4th percentile
wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a large packet.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.10.4-1 (bookworm) | wireshark 1.10.4-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 1.10.4-1 | 1.10.4-1 |
| wireshark | wireshark | >= 0 < 1.10.4-1 | 1.10.4-1 |
| wireshark | wireshark | >= 0 < 1.10.4-1 | 1.10.4-1 |
| wireshark | wireshark | >= 0 < 1.10.4-1 | 1.10.4-1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mvm8-xfgh-xjqv: wiretap/libpcap
ghsa_unreviewed·2022-05-17
CVE-2014-4174 [HIGH] CWE-119 GHSA-mvm8-xfgh-xjqv: wiretap/libpcap
wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a large packet.
OSV
CVE-2014-4174: wiretap/libpcap
osv·2014-06-18·CVSS 9.3
CVE-2014-4174 [CRITICAL] CVE-2014-4174: wiretap/libpcap
wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a large packet.
Red Hat
libpcap: file parser crash (wnpa-sec-2014-05)
vendor_redhat·2014-04-09·CVSS 9.3
CVE-2014-4174 [CRITICAL] libpcap: file parser crash (wnpa-sec-2014-05)
libpcap: file parser crash (wnpa-sec-2014-05)
wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a large packet.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: libpcap (Red Hat Enterprise Linux 6) - Not affected
Package: libpcap (Red Hat Enterprise Linux 7) - Not affected
Package: wireshark (Red Hat Enterprise Linux 7) - Not affected
Packa
Debian
CVE-2014-4174: wireshark - wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 a...
vendor_debian·2014·CVSS 9.3
CVE-2014-4174 [CRITICAL] CVE-2014-4174: wireshark - wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 a...
wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a large packet.
Scope: local
bookworm: resolved (fixed in 1.10.4-1)
bullseye: resolved (fixed in 1.10.4-1)
forky: resolved (fixed in 1.10.4-1)
sid: resolved (fixed in 1.10.4-1)
trixie: resolved (fixed in 1.10.4-1)
No detection rules found.
No public exploits indexed.
arXiv
Exploring Emerging Trends in 5G Malicious Traffic Analysis and Incremental Learning Intrusion Detection Strategies
arxiv_fulltext·2024-02-22
Exploring Emerging Trends in 5G Malicious Traffic Analysis and Incremental Learning Intrusion Detection Strategies
Exploring Emerging Trends in 5G Malicious Traffic Analysis and Incremental Learning Intrusion Detection Strategies
Zihao Wang, Kar Wai Fok, Vrizlynn L. L. Thing
Cybersecurity Strategic Technology Centre
Singapore Technologies Engineering
## Abstract
The popularity of 5G networks poses a huge challenge for malicious traffic detection technology. The reason for this is that as the use of 5G technology increases, so does the risk of malicious traffic activity on 5G networks. Malicious traffic activity in 5G networks not only has the potential to disrupt communication services, but also to compromise sensitive data. This can have serious consequences for individuals and organizations. In this paper, we first provide an in-depth study of 5G technology and 5G security. Next we analyze and di
Bugzilla
CVE-2014-4174 libpcap: file parser crash (wnpa-sec-2014-05)
bugzilla·2014-04-10·CVSS 9.3
CVE-2014-4174 [CRITICAL] CVE-2014-4174 libpcap: file parser crash (wnpa-sec-2014-05)
CVE-2014-4174 libpcap: file parser crash (wnpa-sec-2014-05)
It was reported that the libpcap file parser could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
This is reported to affect Wireshark versions 1.10.0 to 1.10.3 and is fixed in 1.10.4. According to the upstream bug report, it was only ever reproduced in Windows, however the upstream advisory does not indicate that it is Windows-only.
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9753
External References:
http://www.wireshark.org/security/wnpa-sec-2014-05.html
Discussion:
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-4174 to
the following vulnerability:
Name: CVE-2014-4174
URL: http:
http://anonsvn.wireshark.org/viewvc/trunk-1.10/wiretap/libpcap.c?r1=53123&r2=53122&pathrev=53123http://anonsvn.wireshark.org/viewvc?view=revision&revision=53123http://www.wireshark.org/security/wnpa-sec-2014-05.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8808https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9390https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9753http://anonsvn.wireshark.org/viewvc/trunk-1.10/wiretap/libpcap.c?r1=53123&r2=53122&pathrev=53123http://anonsvn.wireshark.org/viewvc?view=revision&revision=53123http://www.wireshark.org/security/wnpa-sec-2014-05.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8808https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9390https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9753
2014-06-18
Published