CVE-2018-7421Infinite Loop in Wireshark

CWE-835Infinite Loop4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.4%
top 37.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 23
Latest updateMay 13

Description

In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the DMP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dmp.c by correctly supporting a bounded number of Security Categories for a DMP Security Classification.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.4.5-1 (bookworm)
Debianwireshark/wireshark< 2.4.5-1+3
NVDwireshark/wireshark2.2.02.2.12+1

🔴Vulnerability Details

2
GHSA
GHSA-7mvc-3rvp-5f4m: In Wireshark 22022-05-13
OSV
CVE-2018-7421: In Wireshark 22018-02-23

📋Vendor Advisories

1
Debian
CVE-2018-7421: wireshark - In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the DMP dissector could go into...2018