LWN.net Logo

wireshark: remote denial of service

Package(s):wireshark CVE #(s):CVE-2012-4048 CVE-2012-4049
Created:August 1, 2012 Updated:December 26, 2012
Description: From the CVE entries:

The PPP dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via a crafted packet, as demonstrated by a usbmon dump. (CVE-2012-4048)

epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (loop and CPU consumption) via a crafted packet. (CVE-2012-4049)

Alerts:
openSUSE openSUSE-SU-2012:0930-1 2012-08-01
Mandriva MDVSA-2012:125 2012-08-06
Mageia MGASA-2012-0206 2012-08-12
Mageia MGASA-2012-0210 2012-08-12
Debian DSA-2590-1 2012-12-26
Mandriva MDVSA-2013:055 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds