Release date:
Updated on:
Affected Systems:
Wireshark 1.6.x
Wireshark 1.4.x
Unaffected system:
Wireshark 1.6.1
Wireshark 1.4.8
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49071
Cve id: CVE-2011-2698
Wireshark (formerly known as Ethereal) is a network group analysis software.
Wireshark has a remote denial-of-service vulnerability when processing specially crafted packets. Remote attackers can exploit this vulnerability to trigger infinite loops and cause the affected applications to crash.
The Wireshark network traffic analyzer's ansi a Interface (IS-634/IOS) parser processes some ansi a map File capture methods in an infinite loop. If Wireshark reads malformed network packets or opens a malicious packet capture file, it may cause a denial of service.
<* Source: vendor
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 723215
Http://seclists.org/oss-sec/2011/q3/130
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Wireshark
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.wireshark.org/