Release date:
Updated on: 2011-09-08
Affected Systems:
Wireshark 1.6.x
Wireshark 1.4.x
Unaffected system:
Wireshark 1.6.2
Wireshark 1.4.9
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49528
Wireshark (formerly known as Ethereal) is a network group analysis software.
Wireshark has the arbitrary code execution vulnerability when processing Lua script files. Remote attackers can exploit this vulnerability to execute the Lua script in a way similar to DLL hijacking.
<* Source: Wireshark (http://www.wireshark.org /)
Link: http://www.wireshark.org/security/wnpa-sec-2011-15.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Wireshark
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.wireshark.org/