Wireshark Frame Metadissector Denial-of-Service Vulnerability (CVE-2014-4020)
Release date:
Updated on:
Affected Systems:
Wireshark 1.10.0-1.10.7
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68044
CVE (CAN) ID: CVE-2014-4020
Wireshark is the most popular network protocol parser.
Wireshark 1.10.0-1.10.7 has an error in frame metadissector. Attackers can use specially crafted data packets to cause a crash.
Simple use of Wireshark
Install Wireshark in Ubuntu 12.04
Starting Wireshark packet capture from common users in Linux
<* Source: vendor
Link: http://secunia.com/advisories/58832/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Wireshark
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.wireshark.org/docs/relnotes/wireshark-1.10.8.html
Http://www.wireshark.org/security/wnpa-sec-2014-07.html
Wireshark details: click here
Wireshark: click here
This article permanently updates the link address: