Wireshark DRDA Dissector 'dissect_drda()' Denial of Service Vulnerability
BID:55284
Info
Wireshark DRDA Dissector 'dissect_drda()' Denial of Service Vulnerability
| Bugtraq ID: | 55284 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2012-3548 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2012 12:00AM |
| Updated: | Aug 30 2013 04:10PM |
| Credit: | Martin Wilck |
| Vulnerable: |
Wireshark Wireshark 1.6.8 Wireshark Wireshark 1.6.7 Wireshark Wireshark 1.6.6 Wireshark Wireshark 1.6.5 Wireshark Wireshark 1.6.4 Wireshark Wireshark 1.6.3 Wireshark Wireshark 1.6.2 Wireshark Wireshark 1.6.1 Wireshark Wireshark 1.6 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Wireshark DRDA Dissector 'dissect_drda()' Denial of Service Vulnerability
Wireshark is prone to a denial-of-service vulnerability.
An attacker can leverage this issue to cause an affected application to consume excessive amount of CPU time and enter an infinite loop which may cause denial-of-service conditions.
Wireshark is prone to a denial-of-service vulnerability.
An attacker can leverage this issue to cause an affected application to consume excessive amount of CPU time and enter an infinite loop which may cause denial-of-service conditions.
Exploit / POC
Wireshark DRDA Dissector 'dissect_drda()' Denial of Service Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A sample '.cap' file is available. Please see the references for more information.
[email protected]
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A sample '.cap' file is available. Please see the references for more information.
[email protected]
Solution / Fix
Wireshark DRDA Dissector 'dissect_drda()' Denial of Service Vulnerability
Solution:
A vendor fix is available in the source code repository. Please see the references for more information.
Solution:
A vendor fix is available in the source code repository. Please see the references for more information.
References
Wireshark DRDA Dissector 'dissect_drda()' Denial of Service Vulnerability
References:
References:
- Wireshark Homepage (Wireshark)