|
|
| |
|
| |
wireshark: multiple vulnerabilities
| Package(s): | wireshark |
CVE #(s): | CVE-2012-0041
CVE-2012-0042
CVE-2012-0043
|
| Created: | January 23, 2012 |
Updated: | January 27, 2012 |
| Description: |
From the Red Hat bugzilla [1], [2], [3]:
Laurent Butti discovered that Wireshark failed to properly check record sizes
for many packet capture file formats. It may be possible to make Wireshark
crash by convincing someone to read a malformed packet trace file. This is
corrected in upstream 1.4.11 and 1.6.5.
Wireshark was improperly handling NULL pointers when displaying packet
information which could lead to a crash. It may be possible to make Wireshark
crash by injecting a malformed packet onto the wire or by convincing someone to
read a malformed packet trace file. This is corrected in upstream 1.4.11 and
1.6.5.
The RLC dissector could overflow a buffer. It may be possible to make
Wireshark crash by injecting a malformed packet onto the wire or by convincing
someone to read a malformed packet trace file. This is corrected in upstream
1.4.11 and 1.6.5. |
| Alerts: |
|
( Log in to post comments)
|
|
|