Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-14938

Опубликовано: 05 авг. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 6.4
CVSS3: 9.1

Описание

An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handle_prism during caplen processing. If the caplen is less than 144, one can cause an integer overflow in the function handle_80211, which will result in an out-of-bounds read and may allow access to sensitive memory (or a denial of service).

РелизСтатусПримечание
bionic

released

1.4.5+repack1-4ubuntu0.18.04.1
cosmic

released

1.4.5+repack1-4ubuntu0.18.10.1
devel

not-affected

1.5.2+repack1-1
disco

not-affected

1.5.2+repack1-1
eoan

not-affected

1.5.2+repack1-1
esm-apps/bionic

released

1.4.5+repack1-4ubuntu0.18.04.1
esm-apps/focal

not-affected

1.5.2+repack1-1
esm-apps/jammy

not-affected

1.5.2+repack1-1
esm-apps/xenial

released

1.4.5+repack1-1ubuntu0.1
esm-infra-legacy/trusty

released

1.4.4+repack1-2ubuntu0.1~esm1

Показывать по

6.4 Medium

CVSS2

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
больше 7 лет назад

An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handle_prism during caplen processing. If the caplen is less than 144, one can cause an integer overflow in the function handle_80211, which will result in an out-of-bounds read and may allow access to sensitive memory (or a denial of service).

CVSS3: 9.1
debian
больше 7 лет назад

An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1. ...

CVSS3: 9.1
github
больше 3 лет назад

An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handle_prism during caplen processing. If the caplen is less than 144, one can cause an integer overflow in the function handle_80211, which will result in an out-of-bounds read and may allow access to sensitive memory (or a denial of service).

6.4 Medium

CVSS2

9.1 Critical

CVSS3