Skip to main content

Wireshark Multiple Vulnerabilities

Last Update Date: 16 Aug 2012 12:30 Release Date: 16 Aug 2012 3698 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities have been identified in Wireshark. A remote user can execute arbitrary code on the target system and cause denial of service conditions.

  1. A remote user can trigger a divide by zero error in the DCP ETSI dissector and the pcap-ng file parser.
  2. A remote user can cause the MongoDB dissector, the AFP dissector and the CTDB dissector to consume excessive CPU resources on the target system.
  3. A remote user can cause the XTP dissector to enter an infinite loop.
  4. A remote user can cause the CIP dissector to consume all available system memory.
  5. A remote user can cause the STUN dissector to crash.
  6. A remote user can cause the EtherCAT Mailbox dissector to abort.
  7. A remote user can trigger a buffer overflow in the ERF dissector, RTPS2 dissector, GSM RLC MAC dissector and Ixia IxVeriWave file parser to execute arbitrary code on the target system.

Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Wireshark versions prior to 1.4.15, 1.6.10, 1.8.2

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (1.4.15, 1.6.10, 1.8.2).

Vulnerability Identifier


Source


Related Link