CVE-2018-18227 log

Source
Severity Low
Remote Yes
Type Denial of service
Description
A flaw has been discovered in wireshark >= 2.6.0 and < 2.6.4 in the  MS-WSP dissector where an invalid type could lead to an assertion failure. This could be used by an attacker to crash wireshark by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Group Package Affected Fixed Severity Status Ticket
AVG-779 wireshark-cli 2.6.3-1 2.6.4-1 High Fixed
Date Advisory Group Package Severity Type
12 Oct 2018 ASA-201810-9 AVG-779 wireshark-cli High multiple issues
References
https://www.wireshark.org/security/wnpa-sec-2018-47
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15119
https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commitdiff;h=536fb9403a5f6bcc060aaa2a1f35d8d0225bb1fd