Resource management error in Wireshark - CVE-2012-2392

 

Resource management error in Wireshark - CVE-2012-2392

Published: June 30, 2012 / Updated: July 29, 2020


Vulnerability identifier: #VU32794
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-2392
CWE-ID: CWE-399
Exploitation vector: Adjecent network
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allows remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) ANSI MAP, (2) ASF, (3) IEEE 802.11, (4) IEEE 802.3, and (5) LTP dissectors.


Affected software

Wireshark
wireshark (Alpine package)

How to mitigate CVE-2012-2392

Install update from vendor's website.

Wireshark - update to 1.4.13
wireshark (Alpine package) - update to 1.4.13-r0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins