Bugzilla – Bug 1102012
VUL-0: CVE-2018-14438: wireshark: create_app_running_mutex sets a NULL DACL
Last modified: 2018-10-04 06:48:30 UTC
CVE-2018-14438 In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-14438 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14921
Windows only