Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wireshark | Wireshark | 1.2.0 (including) | 1.2.0 (including) |
Wireshark | Wireshark | 1.2.1 (including) | 1.2.1 (including) |
Wireshark | Wireshark | 1.2.2 (including) | 1.2.2 (including) |
Wireshark | Wireshark | 1.2.3 (including) | 1.2.3 (including) |
Wireshark | Wireshark | 1.2.4 (including) | 1.2.4 (including) |
Wireshark | Wireshark | 1.2.5 (including) | 1.2.5 (including) |
Wireshark | Wireshark | 1.2.6 (including) | 1.2.6 (including) |
Wireshark | Wireshark | 1.2.7 (including) | 1.2.7 (including) |
Wireshark | Wireshark | 1.2.8 (including) | 1.2.8 (including) |
Wireshark | Wireshark | 1.2.9 (including) | 1.2.9 (including) |
Wireshark | Wireshark | 1.2.10 (including) | 1.2.10 (including) |
Wireshark | Wireshark | 1.2.11 (including) | 1.2.11 (including) |
Wireshark | Wireshark | 1.4.0 (including) | 1.4.0 (including) |
Red Hat Enterprise Linux 4 | RedHat | wireshark-0:1.0.15-2.el4 | * |
Red Hat Enterprise Linux 5 | RedHat | wireshark-0:1.0.15-1.el5_6.4 | * |
Red Hat Enterprise Linux 6 | RedHat | wireshark-0:1.2.13-1.el6_0.1 | * |
Wireshark | Ubuntu | hardy | * |
Wireshark | Ubuntu | karmic | * |
Wireshark | Ubuntu | lucid | * |
Wireshark | Ubuntu | maverick | * |
Wireshark | Ubuntu | upstream | * |