Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Wireshark Multiple Denial of Service Vulnerabilities - April 12 (Windows)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
This host is installed with Wireshark and is prone to multiple denial of service vulnerabilities.
Insight
Insight
The flaws are due to - A NULL pointer dereference error in the ANSI A dissector can be exploited to cause a crash via a specially crafted packet. - An error in the MP2T dissector when allocating memory can be exploited to cause a crash via a specially crafted packet. - An error exists in the pcap and pcap-ng file parsers when reading ERF data and can cause a crash via a specially crafted trace file.
Affected Software
Affected Software
Wireshark versions 1.4.x before 1.4.12 and 1.6.x before 1.6.6 on Windows
Solution
Solution
Upgrade to the Wireshark version 1.4.12, 1.6.6 or later.
Common Vulnerabilities and Exposures (CVE)
References
- http://www.wireshark.org/security/wnpa-sec-2012-07.html
- http://www.wireshark.org/security/wnpa-sec-2012-06.html
- http://www.wireshark.org/security/wnpa-sec-2012-04.html
- http://www.openwall.com/lists/oss-security/2012/03/28/13
- http://anonsvn.wireshark.org/viewvc?view=revision&revision=41001
- http://www.wireshark.org/download