PT-2014-1765 · Wireshark+1 · Wireshark+1
Publicado
2014-06-16
·
Atualizado
2024-06-15
·
CVE-2014-4020
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Wireshark versions 1.10.x through 1.10.7
Description
The issue arises from the interpretation of negative integers as length values in the
dissect frame function, located in epan/dissectors/packet-frame.c, within the frame metadissector of Wireshark. This condition, which should be treated as an error, allows remote attackers to cause a denial of service, resulting in the application crashing when a specially crafted packet is processed.Recommendations
For Wireshark versions 1.10.x through 1.10.7, update to version 1.10.8 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
dissect frame function in the frame metadissector until a patch is applied.Exploit
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Wireshark