CVE-2018-7337Improper Input Validation in Wireshark

Severity
7.5HIGHNVD
EPSS
0.7%
top 27.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateMay 13

Description

In Wireshark 2.4.0 to 2.4.4, the DOCSIS protocol dissector could crash. This was addressed in plugins/docsis/packet-docsis.c by removing the recursive algorithm that had been used for concatenated PDUs.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.4.5-1 (bookworm)
Debianwireshark/wireshark< 2.4.5-1+3
NVDwireshark/wireshark2.4.02.4.4

Also affects: Debian Linux 7.0

🔴Vulnerability Details

2
GHSA
GHSA-96x3-94mh-fx58: In Wireshark 22022-05-13
OSV
CVE-2018-7337: In Wireshark 22018-02-23

📋Vendor Advisories

2
Red Hat
wireshark: DOCSIS dissector crash in packet-docsis.c by injecting a malformed packet2018-02-19
Debian
CVE-2018-7337: wireshark - In Wireshark 2.4.0 to 2.4.4, the DOCSIS protocol dissector could crash. This was...2018

💬Community

2
Bugzilla
CVE-2018-7337 wireshark: DOCSIS dissector crash in packet-docsis.c by injecting a malformed packet [fedora-all]2018-02-26
Bugzilla
CVE-2018-7337 wireshark: DOCSIS dissector crash in packet-docsis.c by injecting a malformed packet2018-02-26