Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-1595

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2012-1595
Last Modified 03 Jan 2013 11:37:26
Published 11 Apr 2012 06:39:26
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2012-1595

Summary

The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a WTAP_ENCAP_ERF file containing an Extension or Multi-Channel header with an invalid pseudoheader size, related to the pcap and pcap-ng file parsers.

Vulnerable Systems

Application

  • Wireshark 1.4.0

  • Wireshark 1.4.1

  • Wireshark 1.4.10

  • Wireshark 1.4.11

  • Wireshark 1.4.2

  • Wireshark 1.4.3

  • Wireshark 1.4.4

  • Wireshark 1.4.5

  • Wireshark 1.4.6

  • Wireshark 1.4.7

  • Wireshark 1.4.8

  • Wireshark 1.4.9

  • Wireshark 1.6.0

  • Wireshark 1.6.1

  • Wireshark 1.6.2

  • Wireshark 1.6.3

  • Wireshark 1.6.4

  • Wireshark 1.6.5


References

CONFIRM - https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6804

CONFIRM - http://www.wireshark.org/security/wnpa-sec-2012-06.html

MLIST - [oss-security] 20120328 Re: CVE Request: Multiple wireshark security flaws resolved in 1.4.12 and 1.6.6

CONFIRM - http://anonsvn.wireshark.org/viewvc?view=revision&revision=41008

SECUNIA - 48986

SUSE - openSUSE-SU-2012:0558

SECUNIA - 48947

Related Patches

Novell SUSE 2012:6170 wireshark security update for SLE 11 SP1 i586

Novell SUSE 2012:6170 wireshark security update for SLE 11 SP1 x86_64

Novell SUSE 2012:8085 wireshark security update for SLE 10 SP4 i586

Novell SUSE 2012:8085 wireshark security update for SLE 10 SP4 x86_64


Last Updated: 27 May 2016 10:49:34