Release date: 2012-03-27
Updated on: 2012-03-28
Affected Systems:
Wireshark 1.6.0-1.6.5
Wireshark 1.4.0-1.4.11
Unaffected system:
Wireshark 1.6.6
Wireshark 1.4.12
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52737
Wireshark (formerly known as Ethereal) is a network group analysis software.
Wireshark implements a security vulnerability when processing malformed ERF data. Attackers can exploit this vulnerability to cause application Denial of Service.
<* Source: Laurent Butti (laurent.butti@orange-ftgroup.com)
Link: https://bugs.wireshark.org/bugzilla/show_bug.cgi? Id = 6804
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Wireshark
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.wireshark.org/security/