Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-0068

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2012-0068
Last Modified 23 Sep 2014 01:20:31
Published 11 Apr 2012 06:39:25
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2012-0068

Summary

The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a Novell catpure file containing a record that is too small.

Vulnerable Systems

Application

  • Wireshark 1.4.0

  • Wireshark 1.4.1

  • Wireshark 1.4.10

  • Wireshark 1.4.11

  • Wireshark 1.4.2

  • Wireshark 1.4.3

  • Wireshark 1.4.4

  • Wireshark 1.4.5

  • Wireshark 1.4.6

  • Wireshark 1.4.7

  • Wireshark 1.4.8

  • Wireshark 1.4.9

  • Wireshark 1.6.0

  • Wireshark 1.6.1

  • Wireshark 1.6.2

  • Wireshark 1.6.3

  • Wireshark 1.6.4

  • Wireshark 1.6.5


References

CONFIRM - https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6670

CONFIRM - http://www.wireshark.org/security/wnpa-sec-2012-01.html

MLIST - [oss-security] 20120119 Re: CVE request: Wireshark multiple vulnerabilities

MLIST - [oss-security] 20120111 Re: CVE request: Wireshark multiple vulnerabilities

CONFIRM - http://anonsvn.wireshark.org/viewvc?view=revision&revision=40169

GENTOO - GLSA-201308-05

SECUNIA - 54425

SECUNIA - 47494

Related Patches

Novell SUSE 2012:5741 wireshark security update for SLE 11 SP1 x86_64

Novell SUSE 2012:5741 wireshark security update for SLE 11 SP1 i586

Novell SUSE 2012:7943 wireshark security update for SLE 10 SP4 i586

Novell SUSE 2012:7943 wireshark security update for SLE 10 SP4 x86_64


Last Updated: 27 May 2016 11:03:24