LWN.net Logo

wireshark: multiple vulnerabilities

Package(s):wireshark CVE #(s):CVE-2012-1593 CVE-2012-1594
Created:April 19, 2012 Updated:April 25, 2012
Description:

From the Red Hat Bugzilla [1, 2]:

CVE-2012-1593: A NULL pointer dereference flaw was found in the way ANSI A dissector of the Wireshark, a network traffic analyzer, processed certain capture files (those causing wireshark to pass NULL packet information via a global variable to the call_dissector() routine). A remote attacker could provide a specially-crafted packet capture file, which once opened by a local unsuspecting user would lead to wireshark executable crash.

CVE-2012-1594: A denial of service flaw was found in the way IEEE 802.11 dissector of Wireshark, a network traffic analyzer, processed certain capture files (16-bit integers were used as counters during loading of capture files for certain protocols). A remote attacker could provide a specially-crafted packet capture file, which once opened by a local unsuspecting user would lead to situation, where wireshark executable would never finish loading of such capture file (infinite loop).

Alerts:
Fedora FEDORA-2012-5243 2012-04-19
openSUSE openSUSE-SU-2012:0558-1 2012-04-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds