CVE-2018-14438
Publication date 20 July 2018
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| wireshark | 18.04 LTS bionic |
Fixed 2.6.3-1~ubuntu18.04.1
|
| 16.04 LTS xenial |
Fixed 2.6.3-1~ubuntu16.04.1
|
|
| 14.04 LTS trusty |
Fixed 2.6.3-1~ubuntu14.04.1
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.5 · High
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N