Infinite Loop Vulnerability in Wireshark CQL Dissector (Versions 2.4.0 to 2.4.5)

Infinite Loop Vulnerability in Wireshark CQL Dissector (Versions 2.4.0 to 2.4.5)

CVE-2018-9257 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

In Wireshark 2.4.0 to 2.4.5, the CQL dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-cql.c by checking for a nonzero number of columns.

Learn more about our Web Application Penetration Testing UK.