Wireshark Multiple Code Execution and Denial of Service Vulnerabilities
Last Update Date:
20 Apr 2011 10:27
Release Date:
20 Apr 2011
6499
Views
RISK: High Risk
TYPE: Servers - Network Management
Multiple vulnerabilities have been identified in Wireshark, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system.
- A buffer overflow error in the DECT dissector when processing malformed data, which could allow code execution via malformed packets or a malicious PCAP file.
- An error in the NFS dissector when processing malformed data, which could be exploited to crash an affected application.
- An error in the X.509if dissector when processing malformed data, which could be exploited to crash an affected application.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- Wireshark versions 1.4.0 through 1.4.4
- Wireshark versions 1.2.0 through 1.2.15
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Wireshark version 1.4.5 or 1.2.16 :
http://www.wireshark.org/download.html
Vulnerability Identifier
Source
Related Link
Share with