CVE Vulnerabilities

CVE-2012-1595

Published: Apr 11, 2012 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4.4 MODERATE
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
NEGLIGIBLE

The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a WTAP_ENCAP_ERF file containing an Extension or Multi-Channel header with an invalid pseudoheader size, related to the pcap and pcap-ng file parsers.

Affected Software

Name Vendor Start Version End Version
Wireshark Wireshark 1.4.0 (including) 1.4.0 (including)
Wireshark Wireshark 1.4.1 (including) 1.4.1 (including)
Wireshark Wireshark 1.4.2 (including) 1.4.2 (including)
Wireshark Wireshark 1.4.3 (including) 1.4.3 (including)
Wireshark Wireshark 1.4.4 (including) 1.4.4 (including)
Wireshark Wireshark 1.4.5 (including) 1.4.5 (including)
Wireshark Wireshark 1.4.6 (including) 1.4.6 (including)
Wireshark Wireshark 1.4.7 (including) 1.4.7 (including)
Wireshark Wireshark 1.4.8 (including) 1.4.8 (including)
Wireshark Wireshark 1.4.9 (including) 1.4.9 (including)
Wireshark Wireshark 1.4.10 (including) 1.4.10 (including)
Wireshark Wireshark 1.4.11 (including) 1.4.11 (including)
Red Hat Enterprise Linux 6 RedHat wireshark-0:1.2.15-2.el6_2.1 *
Wireshark Ubuntu natty *
Wireshark Ubuntu oneiric *
Wireshark Ubuntu upstream *

References