NASLDB: Wireshark 1.4.x < 1.4.13 Multiple Denial of Service Vulnerabilities
General
ID: 59239
Name: Wireshark 1.4.x < 1.4.13 Multiple Denial of Service Vulnerabilities
Summary: Does a version check
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P
CVSS Temporal Vector: CVSS2#E:F/RL:OF/RC:C
Port: –
Family: Windows
Type: Local
Description
The installed version of Wireshark is 1.4.x before 1.4.13. This
version is affected by the following vulnerabilities :
– Input validation errors exist in the dissectors for
ANSI MAP, ASF, BACapp, Bluetooth HCI, IEEE 802.11,
IEEE 802.3, LTP, and R3 that can allow specially crafted
packets to cause the application to enter infinite or
very large loops making it unavailable. (Issues 6805,
7118, 7119, 7120, 7121, 7122, 7124, 7125)
– An input validation error exists in the DIAMETER
dissector that can allow specially crafted packets to
cause improper memory allocation leading to application
crashes. (Issue 7138)
– An unspecified error can cause the application to crash
due to a memory misalignment. Note, for Windows, this
issue only occurs on the Itanium platform. (Issue 7221)
Exploiting
Exploit Available: True
Exploitability Ease: Exploits are available
Sources
CVE: CVE-2012-2392
OSVDB: –
Bugtraq: 53651
scipID: –
Timeline
Vulnerability Disclosure: 2012/05/21
Patch Release: 2012/05/21
Plugin Release: 2012/05/23
Plugin
Version: 1.8
Filename: wireshark_1_4_13.nasl
Filesize: 4544 bytes
MD5 Hash: 6ce890618526b1e5d086f48b4695e802
Identification: SMB/transport
Require Keys: SMB/Wireshark/Installed
Dependencies: "wireshark_installed.nasl"
Copyright: This script is Copyright© 2012 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













