Resource management error in Wireshark - CVE-2012-2392
Published: June 30, 2012 / Updated: July 29, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allows remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) ANSI MAP, (2) ASF, (3) IEEE 802.11, (4) IEEE 802.3, and (5) LTP dissectors.
Affected software
wireshark (Alpine package)
How to mitigate CVE-2012-2392
wireshark (Alpine package) - update to 1.4.13-r0
Links to Public Exploits and PoC-codes
External References
- http://secunia.com/advisories/49226
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:015
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:042
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:080
- http://www.securitytracker.com/id?1027094
- http://www.wireshark.org/security/wnpa-sec-2012-08.html
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6805
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7118
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7119
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7120
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7124
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15604