|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


   
 

CERT-MU AD-2010-11

Multiple Vulnerabilities in Wireshark

Original issue date: 23 June, 2010

Overview

Multiple vulnerabilities have been reported in Wireshark, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system by infecting a series of crafted packets or persuade the victim to read a malformed trace file.

Description

  • SMB dissector Vulnerability

    The vulnerability exists due to a NULL pointer dereference error in the SMB dissector, which could be exploited to crash an affected application. An remote attacker could exploit this vulnerability by sending some malicious packets to cause the application to crash.
  • ASN.1 BER dissector Vulnerability

    The vulnerability is due to buffer overflow error within the ASN.1 BER dissector. A remote attacker could exploit this issue by executing an arbitrary code or crash an affected application.
  • SMB PIPE dissector Vulnerability

    The vulnerability exists in Wireshark by a NULL pointer dereference in the SMB PIPE dissector. An remote attacker could exploit this vulnerability by loading a specailly-crafted trace file or by sending some malicious packets to cause the application to crash.
  • Infinite loop of SigComp Universal Decompressor Vulnerability

    This vulnerability have been caused by an infinite loop in the SigComp Universal Decompressor Virtual Machine, which could be exploited to crash an affected application.
Software Affected

  • Wireshark versions 1.2.0 through 1.2.8
  • Wireshark versions 0.8.20 through 1.0.13Impact

Impact

Severity Rating: High

Solution

Upgrade to Wireshark version 1.0.14 or 1.2.9 :
http://www.wireshark.org/download.html

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind

Vendor Information

Wireshark

http://www.wireshark.org/security/wnpa-sec-2010-06.html
http://www.wireshark.org/security/wnpa-sec-2010-05.html

CVE Name

CVE-2010-2283
CVE-2010-2284
CVE-2010-2285
CVE-2010-2286
CVE-2010-2287

References

Wireshark
http://www.wireshark.org/security/wnpa-sec-2010-06.html http://www.wireshark.org/security/wnpa-sec-2010-05.html

VUPEN
http://www.vupen.com/english/advisories/2010/1418

 
 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed
 
 
 

Last Updated 20-Jul-2011
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +