Wireshark 'airpcap.dll' DLL Loading Arbitrary Code Execution Vulnerability
BID:42630
Info
Wireshark 'airpcap.dll' DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 42630 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2010 12:00AM |
| Updated: | Sep 01 2010 06:37PM |
| Credit: | HD Moore, TheLeader |
| Vulnerable: |
Wireshark Wireshark 1.2.10 Wireshark Wireshark 1.2.9 Wireshark Wireshark 1.2.8 Wireshark Wireshark 1.2.7 Wireshark Wireshark 1.2.6 Wireshark Wireshark 1.2.5 Wireshark Wireshark 1.2.4 Wireshark Wireshark 1.2.3 Wireshark Wireshark 1.2.2 Wireshark Wireshark 1.2.1 Wireshark Wireshark 1.2 Wireshark Wireshark 1.0.15 Wireshark Wireshark 1.0.14 Wireshark Wireshark 1.0.13 Wireshark Wireshark 1.0.12 Wireshark Wireshark 1.0.11 Wireshark Wireshark 1.0.10 Wireshark Wireshark 1.0.9 Wireshark Wireshark 1.0.8 Wireshark Wireshark 1.0.7 Wireshark Wireshark 1.0.6 Wireshark Wireshark 1.0.5 Wireshark Wireshark 1.0.4 Wireshark Wireshark 1.0.3 Wireshark Wireshark 1.0.2 Wireshark Wireshark 1.0.1 Wireshark Wireshark 1.0 |
| Not Vulnerable: |
Wireshark Wireshark 1.4.0 Wireshark Wireshark 1.2.11 Wireshark Wireshark 1.0.16 |
Discussion
Wireshark 'airpcap.dll' DLL Loading Arbitrary Code Execution Vulnerability
Wireshark is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Linked Library (DLL) file.
Wireshark 1.2.10 and prior are vulnerable; other versions may also be affected.
Wireshark is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Linked Library (DLL) file.
Wireshark 1.2.10 and prior are vulnerable; other versions may also be affected.
Exploit / POC
Wireshark 'airpcap.dll' DLL Loading Arbitrary Code Execution Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Wireshark 'airpcap.dll' DLL Loading Arbitrary Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Wireshark 'airpcap.dll' DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Exploiting DLL Hijacking Flaws (hdm)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- Wireshark 1.4.0, 1.2.11, and 1.0.16 Released (Wireshark)
- Wireshark Homepage (Wireshark)
- Microsoft Security Advisory (2269637) (Microsoft)