LWN.net Logo

wireshark: denial of service

Package(s):wireshark CVE #(s):CVE-2012-5239 CVE-2012-3548
Created:October 8, 2012 Updated:March 8, 2013
Description: From the CVE entries:

The Mageia advisory references CVE-2012-5239, which is a duplicate of CVE-2012-3548.

The dissect_drda function in epan/dissectors/packet-drda.c in Wireshark 1.6.x through 1.6.10 and 1.8.x through 1.8.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a small value for a certain length field in a capture file. (CVE-2012-3548)

Alerts:
Mageia MGASA-2012-0284 2012-10-06
Mandriva MDVSA-2013:020 2013-03-08
Mandriva MDVSA-2013:055 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds