CVE-2018-9263 describes a denial-of-service vulnerability in Wireshark versions 2.4.0 through 2.4.5 and 2.2.0 through 2.2.13, where a crafted Kerberos packet could cause the dissector to crash. This vulnerability carries a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, resulting in high availability impact without requiring user interaction or privileges. While the vulnerability is significant, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or notable community discussion or media coverage. The issue was addressed by ensuring a non-zero key length in the Kerberos dissector.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, <= 2.2.13CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* | ||
>= 2.4.0, <= 2.4.5CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.