Wireshark RTP Dissector CVE-2014-2907 Remote Denial of Service Vulnerability
BID:67046
Info
Wireshark RTP Dissector CVE-2014-2907 Remote Denial of Service Vulnerability
| Bugtraq ID: | 67046 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-2907 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 22 2014 12:00AM |
| Updated: | Apr 13 2015 09:51PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Wireshark Wireshark 1.10.6 Wireshark Wireshark 1.10.5 Wireshark Wireshark 1.10.4 Wireshark Wireshark 1.10.3 Wireshark Wireshark 1.10.2 Wireshark Wireshark 1.10.1 Wireshark Wireshark 1.10 Redhat OpenStack 4.0 Redhat OpenStack 3.0 Oracle Solaris 11.2 Gentoo Linux |
| Not Vulnerable: |
Wireshark Wireshark 1.10.7 |
Discussion
Wireshark RTP Dissector CVE-2014-2907 Remote Denial of Service Vulnerability
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark 1.10.0 through versions 1.10.6 are vulnerable.
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark 1.10.0 through versions 1.10.6 are vulnerable.
Exploit / POC
Wireshark RTP Dissector CVE-2014-2907 Remote Denial of Service Vulnerability
A sample pcap file is available. Please see the references for information.
A sample pcap file is available. Please see the references for information.
Solution / Fix
Wireshark RTP Dissector CVE-2014-2907 Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Wireshark RTP Dissector CVE-2014-2907 Remote Denial of Service Vulnerability
References:
References:
- CVE-2014-2907 Denial Of Service(DOS) vulnerability in Wireshark (Oracle)
- Wireshark 1.10.7 Release Notes (Wireshark)
- Wireshark Homepage (Wireshark)
- wnpa-sec-2014-06 · RTP dissector crash (Wireshark)