Wireshark Multiple Vulnerabilities
Last Update Date:
16 Aug 2012 12:30
Release Date:
16 Aug 2012
4223
Views
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
Multiple vulnerabilities have been identified in Wireshark. A remote user can execute arbitrary code on the target system and cause denial of service conditions.
- A remote user can trigger a divide by zero error in the DCP ETSI dissector and the pcap-ng file parser.
- A remote user can cause the MongoDB dissector, the AFP dissector and the CTDB dissector to consume excessive CPU resources on the target system.
- A remote user can cause the XTP dissector to enter an infinite loop.
- A remote user can cause the CIP dissector to consume all available system memory.
- A remote user can cause the STUN dissector to crash.
- A remote user can cause the EtherCAT Mailbox dissector to abort.
- A remote user can trigger a buffer overflow in the ERF dissector, RTPS2 dissector, GSM RLC MAC dissector and Ixia IxVeriWave file parser to execute arbitrary code on the target system.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- Wireshark versions prior to 1.4.15, 1.6.10, 1.8.2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (1.4.15, 1.6.10, 1.8.2).
Vulnerability Identifier
- CVE-2012-4285
- CVE-2012-4286
- CVE-2012-4287
- CVE-2012-4288
- CVE-2012-4289
- CVE-2012-4290
- CVE-2012-4291
- CVE-2012-4292
- CVE-2012-4293
- CVE-2012-4294
- CVE-2012-4295
- CVE-2012-4296
- CVE-2012-4297
- CVE-2012-4298
Source
Related Link
Share with