All errata/sisyphus/ALT-PU-2018-2268-1
ALT-PU-2018-2268-1

Package update wireshark in branch sisyphus

Version2.6.3-alt1.S1
Published2018-09-03
Max severityHIGH
Severity:

Closed issues (4)

CVE-2018-14438
HIGH7.5

In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily.

Published: 2018-07-20Modified: 2024-11-21
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N