High severity7.5NVD Advisory· Published Jul 19, 2018· Updated Jun 17, 2026
CVE-2018-14339
CVE-2018-14339
Description
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE dissector could go into an infinite loop. This was addressed in epan/proto.c by adding offset and length validation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
39- osv-coords38 versionspkg:rpm/opensuse/libmaxminddb&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/spandsp&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/wireshark&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/wireshark&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libmaxminddb&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/libmaxminddb&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/libmaxminddb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/libmaxminddb&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/libmaxminddb&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/spandsp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/spandsp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/spandsp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/spandsp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP1pkg:rpm/suse/spandsp&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/spandsp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/wireshark&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP1pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/wireshark&distro=SUSE%20OpenStack%20Cloud%207
< 1.4.2-lp151.3.3.1+ 37 more
- (no CPE)range: < 1.4.2-lp151.3.3.1
- (no CPE)range: < 0.0.6-lp151.3.3.1
- (no CPE)range: < 3.2.2-lp151.2.9.1
- (no CPE)range: < 3.4.8-1.2
- (no CPE)range: < 1.4.2-1.3.1
- (no CPE)range: < 1.4.2-1.3.1
- (no CPE)range: < 1.4.2-1.3.1
- (no CPE)range: < 1.4.2-1.3.1
- (no CPE)range: < 1.4.2-1.3.1
- (no CPE)range: < 0.0.6-3.2.1
- (no CPE)range: < 0.0.6-3.2.1
- (no CPE)range: < 0.0.6-3.2.1
- (no CPE)range: < 0.0.6-3.2.1
- (no CPE)range: < 0.0.6-3.2.1
- (no CPE)range: < 0.0.6-3.2.1
- (no CPE)range: < 2.4.9-48.29.1
- (no CPE)range: < 2.4.9-48.29.1
- (no CPE)range: < 3.2.2-3.35.2
- (no CPE)range: < 3.2.2-3.35.2
- (no CPE)range: < 2.4.8-3.6.1
- (no CPE)range: < 3.2.2-3.35.2
- (no CPE)range: < 2.4.8-3.6.1
- (no CPE)range: < 3.2.2-3.35.2
- (no CPE)range: < 2.2.16-40.28.1
- (no CPE)range: < 2.4.9-48.29.1
- (no CPE)range: < 2.4.9-48.29.1
- (no CPE)range: < 2.4.9-48.29.1
- (no CPE)range: < 2.4.9-48.29.1
- (no CPE)range: < 2.4.9-48.29.1
- (no CPE)range: < 3.2.2-3.35.2
- (no CPE)range: < 2.2.16-40.28.1
- (no CPE)range: < 2.4.9-48.29.1
- (no CPE)range: < 2.4.9-48.29.1
- (no CPE)range: < 2.4.9-48.29.1
- (no CPE)range: < 3.2.2-3.35.2
- (no CPE)range: < 2.2.16-40.28.1
- (no CPE)range: < 2.4.9-48.29.1
- (no CPE)range: < 2.4.9-48.29.1
Patches
Vulnerability mechanics
References
7- www.securityfocus.com/bid/104847nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1041608nvdThird Party AdvisoryVDB Entry
- bugs.wireshark.org/bugzilla/show_bug.cginvdIssue TrackingVendor Advisory
- lists.debian.org/debian-lts-announce/2018/07/msg00045.htmlnvdMailing ListThird Party Advisory
- www.wireshark.org/security/wnpa-sec-2018-38.htmlnvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.htmlnvd
- code.wireshark.org/review/gitwebnvd
News mentions
0No linked articles in our index yet.