Wireshark Multiple Vulnerabilities
Last Update Date:
12 Jan 2012 10:29
Release Date:
12 Jan 2012
5378
Views
RISK: High Risk
TYPE: Security software and application - Security Software & Appliance
Multiple vulnerabilities have been identified in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a user's system.
- NULL pointer dereference errors when reading certain packet information can be exploited to cause a crash.
- An error within the RLC dissector can be exploited to cause a buffer overflow via a specially crafted RLC packet capture file.
Successful exploitation of this vulnerability may allow execution of arbitrary code. - A weakness within the file parser, which can lead to a crash when handling capture files has also been reported.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- Wireshark 1.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 1.4.11 or 1.6.5.
http://www.wireshark.org/docs/relnotes/wireshark-1.4.11.html
http://www.wireshark.org/docs/relnotes/wireshark-1.6.5.html
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with