CVE-2014-2283
EPSS 3.3%
Description
epan/dissectors/packet-rlc in the RLC dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 uses inconsistent memory-management approaches, which allows remote attackers to cause a denial of service (use-after-free error and application crash) via a crafted UMTS Radio Link Control packet.
How to fix CVE-2014-2283
To remediate CVE-2014-2283, upgrade the affected package to a fixed version below.
- Debian/wireshark—upgrade to 1.10.6-1 or later
Is CVE-2014-2283 being exploited?
Low — EPSS is 3.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.10.6-1