Lucene search

K
f5F5F5:K000138056
HistoryDec 27, 2023 - 12:00 a.m.

K000138056 : Wireshark vulnerability CVE-2018-14438

2023-12-2700:00:00
my.f5.com
5
wireshark
vulnerability
create_app_running_mutex
function
wsutil
file_util
setsecuritydescriptordacl
null dacl
access control arbitarily
cve-2018-14438

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

49.3%

Security Advisory Description

In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily. (CVE-2018-14438)

Impact

There is no impact; F5 products are not affected by this vulnerability.

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

49.3%