Release date: 2012-03-27
Updated on: 2012-03-28
Affected Systems:
Wireshark 1.6.x
Unaffected system:
Wireshark 1.6.6
Wireshark 1.4.12
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52735
Wireshark (formerly known as Ethereal) is a network group analysis software.
Wireshark's security vulnerability in implementation allows attackers to inject malformed packets or induce users to read malformed packet tracking files. Attackers can exploit this vulnerability to cause NULL pointer reference and cause application crash.
<* Source: Wireshark (http://www.wireshark.org /)
Link: http://www.wireshark.org/security/wnpa-sec-2012-04.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Wireshark
---------
Wireshark has released a Security Bulletin (wnpa-sec-2012-04) and corresponding patches for this:
Wnpa-sec-2012-04: Wireshark ansi a dissector crash
Link: http://www.wireshark.org/security/wnpa-sec-2012-04.html