Release date: 2011-11-01
Updated on: 2011-11-03
Affected Systems:
Wireshark 1.6.x
Wireshark 1.4.x
Unaffected system:
Wireshark 1.6.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50486
Cve id: CVE-2011-4102
Wireshark (formerly known as Ethereal) is a network group analysis software.
Wireshark has a buffer overflow vulnerability in the implementation of ERF file reading. Attackers can trick users to read malformed packet tracing files and execute arbitrary code in the affected applications, causing Wireshark to crash.
<* Source: Huzaifa Sidhpurwala
Link: https://bugs.wireshark.org/bugzilla/show_bug.cgi? Id = 6479
Http://www.wireshark.org/security/wnpa-sec-2011-19.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Wireshark
---------
Wireshark has released a Security Bulletin (wnpa-sec-2011-19) and corresponding patches for this:
Wnpa-sec-2011-19: Wireshark ERF file parser vulnerability
Link: http://www.wireshark.org/security/wnpa-sec-2011-19.html