wireshark: yet another pile of dissector flaws
wireshark: yet another pile of dissector flaws
Posted Oct 6, 2014 14:36 UTC (Mon) by raven667 (subscriber, #5198)In reply to: wireshark: yet another pile of dissector flaws by dlang
Parent article: wireshark: yet another pile of dissector flaws
But it's a good point to note that after all these years and CVE numbers, how could they not think about the problem? My guess is that the project doesn't see the wireshark attack vector as particularly likely and so the risk is not serious. Otherwise they'd create a validating bytecode interpreter for processing packet data and port their decoders to it, or they'd separate out the decoders from the UI and create a heavily sandboxed sub-process to process any dirty data.
