wireshark: yet another pile of dissector flaws
wireshark: yet another pile of dissector flaws
Posted Oct 6, 2014 17:27 UTC (Mon) by pizza (subscriber, #46)In reply to: wireshark: yet another pile of dissector flaws by malor
Parent article: wireshark: yet another pile of dissector flaws
Most dissectors are contributed by folks who want to be able to decode $random_protocol they're developing in a lab. It's written according to the protocol specs (if there even are any) and generally assumes that nothing outside the spec will occur.
These vulnerabilities that keep popping up are primarily in the long tail of obscure protocols, not in the core wireshark code that is pretty solid.
Meanwhile, taking advantage of a particular dissector's vulnerabilities would take some seriously targeted attacks.
