Release date: 2012-03-27
Updated on: 2012-03-28
Affected Systems:
Wireshark 1.6.x
Unaffected system:
Wireshark 1.6.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52738
Wireshark (formerly known as Ethereal) is a network group analysis software.
Wireshark security vulnerability in implementation. Attackers can exploit this vulnerability to cause application Denial of Service by injecting malformed packets or enticing users to read malformed packet tracking files.
<* Source: quatechbbelec
Link: https://bugs.wireshark.org/bugzilla/show_bug.cgi? Id = 6809
Http://www.wireshark.org/security/wnpa-sec-2012-05.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Wireshark
---------
Wireshark has released a Security Bulletin (wnpa-sec-2012-05) and corresponding patches for this:
Wnpa-sec-2012-05: Wireshark 802.11 infinite loop
Link: http://www.wireshark.org/security/wnpa-sec-2012-05.html