Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wireshark | Wireshark | 0.10.1 (including) | 0.99.3 (including) |
Red Hat Enterprise Linux 2.1 | RedHat | wireshark-0:0.99.4-AS21.1 | * |
Red Hat Enterprise Linux 3 | RedHat | wireshark-0:0.99.4-EL3.1 | * |
Red Hat Enterprise Linux 4 | RedHat | wireshark-0:0.99.4-EL4.1 | * |
Ethereal | Ubuntu | dapper | * |
Wireshark | Ubuntu | devel | * |
Wireshark | Ubuntu | edgy | * |
Wireshark | Ubuntu | feisty | * |
Wireshark | Ubuntu | gutsy | * |
Wireshark | Ubuntu | hardy | * |
Wireshark | Ubuntu | intrepid | * |
Wireshark | Ubuntu | jaunty | * |
Wireshark | Ubuntu | karmic | * |
Wireshark | Ubuntu | upstream | * |