7.5
CVSSv3

CVE-2018-5336

Published: 11/01/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash. This was addressed in epan/tvbparse.c by limiting the recursion depth.

Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark

debian debian linux 8.0

debian debian linux 7.0

debian debian linux 9.0

Vendor Advisories

It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors/file parsers for IxVeriWave, WCP, JSON, XML, NTP, XMPP and GDB, which could result in denial of service or the execution of arbitrary code For the oldstable distribution (jessie), these problems have been fixed in version 1121+g01b6 ...
Debian Bug report logs - #885831 wireshark: CVE-2017-17935: Denial of service in the File_read_line function in epan/wslua/wslua_filec Package: src:wireshark; Maintainer for src:wireshark is Balint Reczey <rbalint@ubuntucom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 30 Dec 2017 09:00:02 UTC ...
In Wireshark 240 to 243 and 220 to 2211, the JSON, XML, NTP, XMPP, and GDB dissectors could crash This was addressed in epan/tvbparsec by limiting the recursion depth ...