PT-2014-1765 · Wireshark+1 · Wireshark+1

Published

2014-06-16

·

Updated

2024-06-15

·

CVE-2014-4020

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Wireshark versions 1.10.x through 1.10.7
Description The issue arises from the interpretation of negative integers as length values in the dissect frame function, located in epan/dissectors/packet-frame.c, within the frame metadissector of Wireshark. This condition, which should be treated as an error, allows remote attackers to cause a denial of service, resulting in the application crashing when a specially crafted packet is processed.
Recommendations For Wireshark versions 1.10.x through 1.10.7, update to version 1.10.8 or later to resolve the issue. As a temporary workaround, consider restricting the use of the dissect frame function in the frame metadissector until a patch is applied.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1786
BDU:2015-00785
CVE-2014-4020
MGASA-2014-0264
OPENSUSE-SU-2024:10199-1

Affected Products

Alt Linux
Wireshark