CVE Vulnerabilities

CVE-2012-4288

Published: Aug 16, 2012 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.3 LOW
AV:A/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

Integer overflow in the dissect_xtp_ecntl function in epan/dissectors/packet-xtp.c in the XTP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop or application crash) via a large value for a span length.

Affected Software

Name Vendor Start Version End Version
Opensuse Opensuse 11.4 (including) 11.4 (including)
Opensuse Opensuse 12.1 (including) 12.1 (including)
Sunos Sun 5.11 (including) 5.11 (including)
Red Hat Enterprise Linux 6 RedHat wireshark-0:1.8.10-4.el6 *
Wireshark Ubuntu hardy *
Wireshark Ubuntu natty *
Wireshark Ubuntu oneiric *
Wireshark Ubuntu precise *
Wireshark Ubuntu quantal *
Wireshark Ubuntu raring *
Wireshark Ubuntu saucy *
Wireshark Ubuntu upstream *

References