All errata/p8/ALT-PU-2018-2276-1
ALT-PU-2018-2276-1

Package update wireshark in branch p8

Version2.6.3-alt1.M80P.1
Published2018-09-04
Max severityHIGH
Severity:

Closed issues (4)

CVE-2018-14438
HIGH7.5

In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily.

Published: 2018-07-20Modified: 2024-11-21
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N