Wireshark issued security patches for three critical vulnerabilities that allow an unauthenticated, remote attacker to crash the vulnerable installations leads to DoS condition.
Wireshark is the most famous open source network protocol analyzer used by organizations and individuals for analyzing network packets and displaying detailed information about them.
Cisco demonstrates the Proof-of-concept (PoC) the exploit of this vulnerability is publicly available.
#Wireshark 2.6.3 has been released. Enjoy.https://t.co/4VUuRv0MZ9
— Wireshark Foundation (@WiresharkNews) August 29, 2018
Wireshark Security Patches
Bluetooth ATT dissector component – CVE-2018-16056
The vulnerability resides with Bluetooth Attribute Protocol (ATT) dissector component allows an attacker could exploit the vulnerability by injecting a malicious packet into a network that to be processed by the vulnerable application or by convincing a user to open the malicious packet trace file.
Successful exploitation of the vulnerability could crash the Bluetooth ATT dissector component resulting in a DoS condition.
The vulnerability affects 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, it has been fixed with 2.6.3, 2.4.9, and 2.2.17 and they are available to download from here.
Radiotap dissector component – CVE-2018-16057
The vulnerability is because of insufficient bound checks with eee80211_radiotap_iterator_next() the function allows an attacker could exploit the vulnerability by injecting a malicious packet into the network that to be processed by the vulnerable application or by convincing a user to open the malicious packet trace file.
Successful exploitation of the vulnerability could crash the Radiotap dissector component resulting in a DoS condition. The vulnerability affects 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, it has been fixed with 2.6.3, 2.4.9, and 2.2.17.
Audio/Video Distribution Transport Protocol – CVE-2018-16058
The vulnerability exists as the source code epan/dissectors/packet-btavdtp.c of the vulnerable software improperly initializes the data structure. An attacker could exploit the vulnerability by injecting a malicious packet into a network that to be processed by the vulnerable application or by convincing a user to open the malicious packet trace file.
Successful exploitation of the vulnerability could crash the AVDTP dissector component resulting in a DoS condition. The vulnerability affects 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, it has been fixed with 2.6.3, 2.4.9, and 2.2.17.
Cisco recommends administrators to both firewall and antivirus applications to minimize the impact of threats and IP based ACL to allow only trusted IP’s to access the vulnerable system.
Also Read
Cisco Released Security Updates for Multiple Vulnerabilities that Affected Cisco Products
16 Years Old Australian Teen Hacked into Apple’s Secure Network & Download the Sensitive Files
Perform Vulnerability Scanning in Your Network using Maltego