PT-2009-5558 · Wireshark · Wireshark
Adrian Dimcev
·
Published
2009-09-18
·
Updated
2024-06-15
·
CVE-2009-3243
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Wireshark versions 1.2.0 through 1.2.1
Description
The issue is related to an unspecified vulnerability in the TLS dissector. It allows remote attackers to cause a denial of service, resulting in an application crash, via unknown vectors related to TLS 1.2 conversations when running on Windows.
Recommendations
For Wireshark versions 1.2.0 and 1.2.1, consider disabling the TLS dissector as a temporary workaround until a patch is available. Restrict access to TLS 1.2 conversations to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wireshark