Skip to main content

Wireshark Multiple Vulnerabilities

Last Update Date: 12 Jan 2012 10:29 Release Date: 12 Jan 2012 4877 Views

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a user's system.

  1. NULL pointer dereference errors when reading certain packet information can be exploited to cause a crash.
  2. An error within the RLC dissector can be exploited to cause a buffer overflow via a specially crafted RLC packet capture file.
    Successful exploitation of this vulnerability may allow execution of arbitrary code. 
  3. A weakness within the file parser, which can lead to a crash when handling capture files has also been reported.

Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Wireshark 1.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

 


Vulnerability Identifier

  • No CVE information is available

Source


Related Link