Vulnerability record · CVE-2014-2299 · published 11 March 2014
CVE-2014-2299: Wireshark MPEG parser buffer overflow in mpeg_read
Wireshark · Wireshark
Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 contain a buffer overflow in the mpeg_read function in wiretap/mpeg.c, triggered by a large record in MPEG data. A crafted capture file or stream can crash the application or potentially allow code execution. The flaw is remotely reachable and requires no authentication.
Description
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 2.0 score of 9.3 with complete confidentiality, integrity, and availability impact, plus available exploit code and high EPSS, though no confirmed in-the-wild exploitation.
What it is
Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 contain a buffer overflow in the mpeg_read function in wiretap/mpeg.c, triggered by a large record in MPEG data. A crafted capture file or stream can crash the application or potentially allow code execution. The flaw is remotely reachable and requires no authentication.
Impact
An attacker can cause a denial of service by crashing Wireshark, or potentially execute arbitrary code in the context of the user running Wireshark.
Attack surface
Reached by supplying a malicious MPEG capture file or stream that Wireshark parses; no authentication is required, but some user interaction (opening or capturing the file) is implied by the AV:N/AC:M vector.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.474 (98.8th percentile) and a public Exploit-DB entry (33069) exists, indicating exploit code is available.
What to do
- Upgrade Wireshark to 1.8.13, 1.10.6, or later
- Apply vendor patches from Red Hat, Debian, or openSUSE advisories
- Avoid opening untrusted MPEG capture files with affected Wireshark versions
- Restrict capture file processing to trusted sources or sandboxed environments
Detection
- Monitor for Wireshark crashes or abnormal termination when processing MPEG files
- Inspect capture files for oversized MPEG records before opening
- Review endpoint logs for Wireshark process crashes correlated with file opens
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-2299 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-2299), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.