|
|
| |
|
| |
wireshark: multiple vulnerabilities
| Package(s): | wireshark |
CVE #(s): | CVE-2012-1593
CVE-2012-1594
|
| Created: | April 19, 2012 |
Updated: | April 25, 2012 |
| Description: |
From the Red Hat Bugzilla [1, 2]:
CVE-2012-1593: A NULL pointer dereference flaw was found in the way ANSI A dissector of the
Wireshark, a network traffic analyzer, processed certain capture files (those
causing wireshark to pass NULL packet information via a global variable to the
call_dissector() routine). A remote attacker could provide a specially-crafted
packet capture file, which once opened by a local unsuspecting user would lead
to wireshark executable crash.
CVE-2012-1594: A denial of service flaw was found in the way IEEE 802.11 dissector of
Wireshark, a network traffic analyzer, processed certain capture files (16-bit
integers were used as counters during loading of capture files for certain
protocols). A remote attacker could provide a specially-crafted packet capture
file, which once opened by a local unsuspecting user would lead to situation,
where wireshark executable would never finish loading of such capture file
(infinite loop). |
| Alerts: |
|
( Log in to post comments)
|
|
|