CVE-2014-2299
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.
- Wireshark
- = 1.8.0, 1.8.1, 1.8.2, 1.8.3, 1.8.4, 1.8.5, 1.8.6, 1.8.7, 1.8.8, 1.8.9, 1.8.10, 1.8.11, 1.8.12
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 47.4% (99th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2014-03-11
CVE-2014-2299 at NVD
6 known exploits for CVE-2014-2299
Proof-of-concept code and exploit modules indexed by Sploitus
Wireshark <= 1.8.12/1.10.5 wiretap/mpeg.c Stack Buffer Overflow
Wireshark 1.8.12/1.10.5 - wiretap/mpeg.c Stack Buffer Overflow (Metasploit)
Wireshark 1.8.12/1.10.5 wiretap/mpeg.c Stack Buffer Overflow
Wireshark 1.8.12/1.10.5 wiretap/mpeg.c Stack Buffer Overflow
Wireshark MPEG File Parser 'wiretap/mpeg.c'缓冲区溢出漏洞
Wireshark wiretap/mpeg.c Stack Buffer Overflow