Skip to main content

Wireshark Multiple Denial of Service Vulnerabilities

Last Update Date: 19 Dec 2013 17:59 Release Date: 19 Dec 2013 3023 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).

  1. An error within the SIP dissector (epan/dissectors/packet-sip.c) can be exploited to cause an infinite loop.
  2. An error within the BSSGP dissector can be exploited to cause a crash. This vulnerability is identified in versions 1.10.0 through 1.10.3.
  3. An error within the NTLMSSP v2 dissector can be exploited to cause a crash.

Impact

  • Denial of Service

System / Technologies affected

  • The vulnerabilities #1 and #3 are identified in versions 1.8.0 through 1.8.11 and 1.10.0 through 1.10.3.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 1.8.12 or 1.10.4.

Vulnerability Identifier


Source


Related Link