CVE-2014-5163
EPSS 0.74%
Description
The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management dissectors in Wireshark 1.10.x before 1.10.9 does not completely initialize a certain buffer, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
How to fix CVE-2014-5163
To remediate CVE-2014-5163, upgrade the affected package to a fixed version below.
- Debian/wireshark—upgrade to 1.12.0+git+4fab41a1-1 or later
Is CVE-2014-5163 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.12.0+git+4fab41a1-1