Release date: 2012-03-27
Updated on: 2012-03-28
Affected Systems:
Wireshark 1.6.x
Unaffected system:
Wireshark 1.6.6
Wireshark 1.4.12
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52736
Wireshark (formerly known as Ethereal) is a network group analysis software.
Wireshark security vulnerability in implementation. Attackers can exploit this vulnerability to cause application crash by injecting malformed packets or enticing users to read malformed packet tracking files.
<* Source: Wireshark (http://www.wireshark.org /)
Link: http://www.wireshark.org/security/wnpa-sec-2012-07.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Wireshark
---------
Wireshark has released a Security Bulletin (wnpa-sec-2012-07) and corresponding patches for this:
Wnpa-sec-2012-07: Wireshark MP2T memory allocation flaw
Link: http://www.wireshark.org/security/wnpa-sec-2012-07.html