Wireshark Dissector LWRES Multiple Buffer Overflow Vulnerabilities
BID:37985
Info
Wireshark Dissector LWRES Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 37985 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-0304 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2010 12:00AM |
| Updated: | Apr 13 2015 10:04PM |
| Credit: | Babi |
| Vulnerable: |
Wireshark Wireshark 1.2.5 Wireshark Wireshark 1.2.4 Wireshark Wireshark 1.2.3 Wireshark Wireshark 1.2.2 Wireshark Wireshark 1.2.1 Wireshark Wireshark 1.2 Wireshark Wireshark 1.0.10 Wireshark Wireshark 1.0.9 Wireshark Wireshark 1.0.8 Wireshark Wireshark 1.0.7 Wireshark Wireshark 1.0.6 Wireshark Wireshark 1.0.5 Wireshark Wireshark 1.0.4 Wireshark Wireshark 1.0.3 Wireshark Wireshark 1.0.2 Wireshark Wireshark 1.0.1 Wireshark Wireshark 1.0 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise 11 SuSE SUSE Linux Enterprise 10 SP3 SuSE SUSE Linux Enterprise 10 SP2 S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server Redhat Desktop 3.0 Pardus Linux 2009 0 Ethereal Group Ethereal 0.99 Ethereal Group Ethereal 0.10.14 Ethereal Group Ethereal 0.10.13 Ethereal Group Ethereal 0.10.12 Ethereal Group Ethereal 0.10.11 Ethereal Group Ethereal 0.10.10 Ethereal Group Ethereal 0.10.9 Ethereal Group Ethereal 0.10.8 Ethereal Group Ethereal 0.10.7 Ethereal Group Ethereal 0.10.6 Ethereal Group Ethereal 0.10.5 Ethereal Group Ethereal 0.10.4 Ethereal Group Ethereal 0.10.3 Ethereal Group Ethereal 0.10.2 Ethereal Group Ethereal 0.10.1 Ethereal Group Ethereal 0.10 .10 Ethereal Group Ethereal 0.10 Ethereal Group Ethereal 0.9.16 Ethereal Group Ethereal 0.9.15 Ethereal Group Ethereal 0.9.14 Ethereal Group Ethereal 0.9.13 Ethereal Group Ethereal 0.9.12 Ethereal Group Ethereal 0.9.11 Ethereal Group Ethereal 0.9.10 Ethereal Group Ethereal 0.9.9 Ethereal Group Ethereal 0.9.8 Ethereal Group Ethereal 0.9.7 Ethereal Group Ethereal 0.9.6 Ethereal Group Ethereal 0.9.5 Ethereal Group Ethereal 0.9.4 Ethereal Group Ethereal 0.9.3 Ethereal Group Ethereal 0.9.2 Ethereal Group Ethereal 0.9.1 Ethereal Group Ethereal 0.9 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Messaging Storage Server 4.0 Avaya Messaging Storage Server 3.1 SP1 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Aura System Platform 1.0 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 3.0 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Communication Manager 4.0 Avaya Aura Communication Manager 4.0 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: |
Wireshark Wireshark 1.2.6 Avaya Aura SIP Enablement Services 5.2.1 SSP#1 |
Discussion
Wireshark Dissector LWRES Multiple Buffer Overflow Vulnerabilities
Wireshark is prone to multiple buffer-overflow vulnerabilities.
Exploiting these issues may allow attackers to crash the application and deny service to legitimate users. Attackers may also execute arbitrary code in the context of vulnerable users running the application.
These issues affect Wireshark 0.9.0 through 1.2.5.
Wireshark is prone to multiple buffer-overflow vulnerabilities.
Exploiting these issues may allow attackers to crash the application and deny service to legitimate users. Attackers may also execute arbitrary code in the context of vulnerable users running the application.
These issues affect Wireshark 0.9.0 through 1.2.5.
Exploit / POC
Wireshark Dissector LWRES Multiple Buffer Overflow Vulnerabilities
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploits are available:
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploits are available:
Solution / Fix
Wireshark Dissector LWRES Multiple Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 ia-64
Debian Linux 5.0 alpha
Debian Linux 5.0 mipsel
Debian Linux 5.0 armel
Debian Linux 5.0 mips
Debian Linux 5.0 ia-32
Debian Linux 5.0 s/390
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 ia-64
-
Debian tshark_1.0.2-3+lenny8_ia64.deb
http://security.debian.org/pool/updates/main/w/wireshark/tshark_1.0.2- 3+lenny8_ia64.deb -
Debian wireshark-common_1.0.2-3+lenny8_ia64.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-com mon_1.0.2-3+lenny8_ia64.deb -
Debian wireshark-dev_1.0.2-3+lenny8_ia64.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-dev _1.0.2-3+lenny8_ia64.deb -
Debian wireshark_1.0.2-3+lenny8_ia64.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark_1.0 .2-3+lenny8_ia64.deb
Debian Linux 5.0 alpha
-
Debian tshark_1.0.2-3+lenny8_alpha.deb
http://security.debian.org/pool/updates/main/w/wireshark/tshark_1.0.2- 3+lenny8_alpha.deb -
Debian wireshark-common_1.0.2-3+lenny8_alpha.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-com mon_1.0.2-3+lenny8_alpha.deb -
Debian wireshark-dev_1.0.2-3+lenny8_alpha.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-dev _1.0.2-3+lenny8_alpha.deb -
Debian wireshark_1.0.2-3+lenny8_alpha.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark_1.0 .2-3+lenny8_alpha.deb
Debian Linux 5.0 mipsel
-
Debian tshark_1.0.2-3+lenny8_mipsel.deb
http://security.debian.org/pool/updates/main/w/wireshark/tshark_1.0.2- 3+lenny8_mipsel.deb -
Debian wireshark-common_1.0.2-3+lenny8_mipsel.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-com mon_1.0.2-3+lenny8_mipsel.deb -
Debian wireshark-dev_1.0.2-3+lenny8_mipsel.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-dev _1.0.2-3+lenny8_mipsel.deb -
Debian wireshark_1.0.2-3+lenny8_mipsel.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark_1.0 .2-3+lenny8_mipsel.deb
Debian Linux 5.0 armel
-
Debian tshark_1.0.2-3+lenny8_armel.deb
http://security.debian.org/pool/updates/main/w/wireshark/tshark_1.0.2- 3+lenny8_armel.deb -
Debian wireshark-common_1.0.2-3+lenny8_armel.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-com mon_1.0.2-3+lenny8_armel.deb -
Debian wireshark-dev_1.0.2-3+lenny8_armel.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-dev _1.0.2-3+lenny8_armel.deb -
Debian wireshark_1.0.2-3+lenny8_armel.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark_1.0 .2-3+lenny8_armel.deb
Debian Linux 5.0 mips
-
Debian tshark_1.0.2-3+lenny8_mips.deb
http://security.debian.org/pool/updates/main/w/wireshark/tshark_1.0.2- 3+lenny8_mips.deb -
Debian wireshark-common_1.0.2-3+lenny8_mips.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-com mon_1.0.2-3+lenny8_mips.deb -
Debian wireshark-dev_1.0.2-3+lenny8_mips.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-dev _1.0.2-3+lenny8_mips.deb -
Debian wireshark_1.0.2-3+lenny8_mips.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark_1.0 .2-3+lenny8_mips.deb
Debian Linux 5.0 ia-32
-
Debian tshark_1.0.2-3+lenny8_i386.deb
http://security.debian.org/pool/updates/main/w/wireshark/tshark_1.0.2- 3+lenny8_i386.deb -
Debian wireshark-common_1.0.2-3+lenny8_i386.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-com mon_1.0.2-3+lenny8_i386.deb -
Debian wireshark-dev_1.0.2-3+lenny8_i386.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-dev _1.0.2-3+lenny8_i386.deb -
Debian wireshark_1.0.2-3+lenny8_i386.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark_1.0 .2-3+lenny8_i386.deb
Debian Linux 5.0 s/390
-
Debian tshark_1.0.2-3+lenny8_s390.deb
http://security.debian.org/pool/updates/main/w/wireshark/tshark_1.0.2- 3+lenny8_s390.deb -
Debian wireshark-common_1.0.2-3+lenny8_s390.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-com mon_1.0.2-3+lenny8_s390.deb -
Debian wireshark-dev_1.0.2-3+lenny8_s390.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark-dev _1.0.2-3+lenny8_s390.deb -
Debian wireshark_1.0.2-3+lenny8_s390.deb
http://security.debian.org/pool/updates/main/w/wireshark/wireshark_1.0 .2-3+lenny8_s390.deb
References
Wireshark Dissector LWRES Multiple Buffer Overflow Vulnerabilities
References:
References:
- Wireshark Homepage (Wireshark)
- ASA-2010-116 wireshark security update (RHSA-2010-0360) (Avaya)
- wnpa-sec-2010-02 (Wireshark)