Wireshark MPEG File Parser 'wiretap/mpeg.c' Buffer Overflow Vulnerability
BID:66066
Info
Wireshark MPEG File Parser 'wiretap/mpeg.c' Buffer Overflow Vulnerability
| Bugtraq ID: | 66066 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-2299 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2014 12:00AM |
| Updated: | Apr 13 2015 09:46PM |
| Credit: | Wesley Neelen. |
| Vulnerable: |
SuSE openSUSE 11.4 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 5 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 CentOS CentOS 5 Avaya Proactive Contact 5.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.2 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: | |
Exploit / POC
Wireshark MPEG File Parser 'wiretap/mpeg.c' Buffer Overflow Vulnerability
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
The following exploit code is available:
[email protected]
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
The following exploit code is available:
[email protected]
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Wireshark MPEG File Parser 'wiretap/mpeg.c' Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5 x86_64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva dumpcap-1.8.13-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64wireshark-devel-1.8.13-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64wireshark2-1.8.13-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva rawshark-1.8.13-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tshark-1.8.13-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva wireshark-1.8.13-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva wireshark-tools-1.8.13-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
Wireshark MPEG File Parser 'wiretap/mpeg.c' Buffer Overflow Vulnerability
References:
References:
- Bug 9843 - MPEG file parser buffer overflow (Wireshark)
- Wireshark 1.10.6 Release Notes (Wireshark)
- Wireshark 1.8.13 Release Notes (Wireshark)
- Wireshark Homepage (Wireshark)
- [CentOS-announce] CESA-2014:0341 Moderate CentOS 5 wireshark Update (CentOS)
- [CentOS-announce] CESA-2014:0342 Moderate CentOS 6 wireshark Update (CentOS)
- ASA-2014-176 (Avaya)
- ELSA-2014-0341 Moderate: Oracle Linux 5 wireshark security update (Oracle)
- ELSA-2014-0342 Moderate: Oracle Linux 6 wireshark security update (Oracle)
- Moderate: wireshark security update (Red Hat)
- Moderate: wireshark security update (Red Hat)
- wnpa-sec-2014-04 · MPEG file parser buffer overflow (Wireshark)