Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-1593

Overview

Vulnerability Score 3.3 3.3
CVE Id CVE-2012-1593
Last Modified 13 Aug 2012 11:36:04
Published 11 Apr 2012 06:39:26
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector ADJACENT_NETWORK
Access Complexity LOW
Authentication NONE

CVE-2012-1593

Summary

epan/dissectors/packet-ansi_a.c in the ANSI A dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet.

Vulnerable Systems

Application

  • Wireshark 1.4.0

  • Wireshark 1.4.1

  • Wireshark 1.4.10

  • Wireshark 1.4.11

  • Wireshark 1.4.2

  • Wireshark 1.4.3

  • Wireshark 1.4.4

  • Wireshark 1.4.5

  • Wireshark 1.4.6

  • Wireshark 1.4.7

  • Wireshark 1.4.8

  • Wireshark 1.4.9


References

CONFIRM - https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6823

CONFIRM - http://www.wireshark.org/security/wnpa-sec-2012-04.html

MLIST - [oss-security] 20120328 Re: CVE Request: Multiple wireshark security flaws resolved in 1.4.12 and 1.6.6

CONFIRM - http://anonsvn.wireshark.org/viewvc?view=revision&revision=40962

SECUNIA - 48986

SUSE - openSUSE-SU-2012:0558

Related Patches

Novell SUSE 2012:6170 wireshark security update for SLE 11 SP1 i586

Novell SUSE 2012:6170 wireshark security update for SLE 11 SP1 x86_64

Novell SUSE 2012:8085 wireshark security update for SLE 10 SP4 i586

Novell SUSE 2012:8085 wireshark security update for SLE 10 SP4 x86_64


Last Updated: 27 May 2016 10:49:34